5.3

CVE-2025-20153

Cisco ESA mail Bypass

A vulnerability in the email filtering mechanism of Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to bypass the configured rules and allow emails that should have been denied to flow through an affected device.  

This vulnerability is due to improper handling of email that passes through an affected device. An attacker could exploit this vulnerability by sending a crafted email through the affected device. A successful exploit could allow the attacker to bypass email filters on the affected device.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Secure Email Gateway Version 13.0.0-392
Cisco ≫ Secure Email Gateway Version 13.0.5-007
Cisco ≫ Secure Email Gateway Version 13.5.1-277
Cisco ≫ Secure Email Gateway Version 13.5.4-038
Cisco ≫ Secure Email Gateway Version 14.0.0-698
Cisco ≫ Secure Email Gateway Version 14.2.0-620
Cisco ≫ Secure Email Gateway Version 14.2.1-020
Cisco ≫ Secure Email Gateway Version 14.3.0-032
Cisco ≫ Secure Email Gateway Version 15.0.0-104
Cisco ≫ Secure Email Gateway Version 15.0.1-030
Cisco ≫ Secure Email Gateway Version 15.0.3-002
Cisco ≫ Secure Email Gateway Version 15.5.0-048
Cisco ≫ Secure Email Gateway Version 15.5.1-055
Cisco ≫ Secure Email Gateway Version 15.5.2-018
Cisco ≫ Secure Email Gateway Version 16.0.0-050
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.35% 0.27
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Cisco PSIRT 5.8 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-mailpol-bypass-5nVcJZMw
Vendor Advisory