5.8
CVE-2025-20153
- EPSS 0.09%
- Veröffentlicht 19.02.2025 16:15:40
- Zuletzt bearbeitet 31.07.2025 12:40:47
- Quelle psirt@cisco.com
- CVE-Watchlists
- Unerledigt
A vulnerability in the email filtering mechanism of Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to bypass the configured rules and allow emails that should have been denied to flow through an affected device. This vulnerability is due to improper handling of email that passes through an affected device. An attacker could exploit this vulnerability by sending a crafted email through the affected device. A successful exploit could allow the attacker to bypass email filters on the affected device.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Secure Email Gateway Version13.0.0-392
Cisco ≫ Secure Email Gateway Version13.0.5-007
Cisco ≫ Secure Email Gateway Version13.5.1-277
Cisco ≫ Secure Email Gateway Version13.5.4-038
Cisco ≫ Secure Email Gateway Version14.0.0-698
Cisco ≫ Secure Email Gateway Version14.2.0-620
Cisco ≫ Secure Email Gateway Version14.2.1-020
Cisco ≫ Secure Email Gateway Version14.3.0-032
Cisco ≫ Secure Email Gateway Version15.0.0-104
Cisco ≫ Secure Email Gateway Version15.0.1-030
Cisco ≫ Secure Email Gateway Version15.0.3-002
Cisco ≫ Secure Email Gateway Version15.5.0-048
Cisco ≫ Secure Email Gateway Version15.5.1-055
Cisco ≫ Secure Email Gateway Version15.5.2-018
Cisco ≫ Secure Email Gateway Version16.0.0-050
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.09% | 0.259 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
|
| psirt@cisco.com | 5.8 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.