6.7

CVE-2025-20185

A vulnerability in the implementation of the remote access functionality of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, Cisco Secure Email Gateway, and Cisco Secure Web Appliance could allow an authenticated, local attacker to elevate privileges to root. The attacker must authenticate with valid administrator credentials.

This vulnerability is due to an architectural flaw in the password generation algorithm for the remote access functionality. An attacker could exploit this vulnerability by generating a temporary password for the service account. A successful exploit could allow the attacker to execute arbitrary commands as root and access the underlying operating system.
Note: The Security Impact Rating (SIR) for this vulnerability is Medium due to the unrestricted scope of information that is accessible to an attacker.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CiscoAsyncos Version13.0.0-392
   CiscoSecure Email And Web Manager Virtual Appliance M100v Version-
   CiscoSecure Email And Web Manager Virtual Appliance M300v Version-
   CiscoSecure Email And Web Manager Virtual Appliance M600v Version-
   CiscoSecure Email And Web Manager M170 Version-
   CiscoSecure Email And Web Manager M190 Version-
   CiscoSecure Email And Web Manager M195 Version-
   CiscoSecure Email And Web Manager M380 Version-
   CiscoSecure Email And Web Manager M390 Version-
   CiscoSecure Email And Web Manager M390x Version-
   CiscoSecure Email And Web Manager M395 Version-
   CiscoSecure Email And Web Manager M680 Version-
   CiscoSecure Email And Web Manager M690 Version-
   CiscoSecure Email And Web Manager M690x Version-
   CiscoSecure Email And Web Manager M695 Version-
CiscoAsyncos Version13.0.5-007
   CiscoSecure Email And Web Manager Virtual Appliance M100v Version-
   CiscoSecure Email And Web Manager Virtual Appliance M300v Version-
   CiscoSecure Email And Web Manager Virtual Appliance M600v Version-
   CiscoSecure Email And Web Manager M170 Version-
   CiscoSecure Email And Web Manager M190 Version-
   CiscoSecure Email And Web Manager M195 Version-
   CiscoSecure Email And Web Manager M380 Version-
   CiscoSecure Email And Web Manager M390 Version-
   CiscoSecure Email And Web Manager M390x Version-
   CiscoSecure Email And Web Manager M395 Version-
   CiscoSecure Email And Web Manager M680 Version-
   CiscoSecure Email And Web Manager M690 Version-
   CiscoSecure Email And Web Manager M690x Version-
   CiscoSecure Email And Web Manager M695 Version-
CiscoAsyncos Version13.5.1-277
   CiscoSecure Email And Web Manager Virtual Appliance M100v Version-
   CiscoSecure Email And Web Manager Virtual Appliance M300v Version-
   CiscoSecure Email And Web Manager Virtual Appliance M600v Version-
   CiscoSecure Email And Web Manager M170 Version-
   CiscoSecure Email And Web Manager M190 Version-
   CiscoSecure Email And Web Manager M195 Version-
   CiscoSecure Email And Web Manager M380 Version-
   CiscoSecure Email And Web Manager M390 Version-
   CiscoSecure Email And Web Manager M390x Version-
   CiscoSecure Email And Web Manager M395 Version-
   CiscoSecure Email And Web Manager M680 Version-
   CiscoSecure Email And Web Manager M690 Version-
   CiscoSecure Email And Web Manager M690x Version-
   CiscoSecure Email And Web Manager M695 Version-
CiscoAsyncos Version13.5.4-038
   CiscoSecure Email And Web Manager Virtual Appliance M100v Version-
   CiscoSecure Email And Web Manager Virtual Appliance M300v Version-
   CiscoSecure Email And Web Manager Virtual Appliance M600v Version-
   CiscoSecure Email And Web Manager M170 Version-
   CiscoSecure Email And Web Manager M190 Version-
   CiscoSecure Email And Web Manager M195 Version-
   CiscoSecure Email And Web Manager M380 Version-
   CiscoSecure Email And Web Manager M390 Version-
   CiscoSecure Email And Web Manager M390x Version-
   CiscoSecure Email And Web Manager M395 Version-
   CiscoSecure Email And Web Manager M680 Version-
   CiscoSecure Email And Web Manager M690 Version-
   CiscoSecure Email And Web Manager M690x Version-
   CiscoSecure Email And Web Manager M695 Version-
CiscoAsyncos Version14.0.0-698
   CiscoSecure Email And Web Manager Virtual Appliance M100v Version-
   CiscoSecure Email And Web Manager Virtual Appliance M300v Version-
   CiscoSecure Email And Web Manager Virtual Appliance M600v Version-
   CiscoSecure Email And Web Manager M170 Version-
   CiscoSecure Email And Web Manager M190 Version-
   CiscoSecure Email And Web Manager M195 Version-
   CiscoSecure Email And Web Manager M380 Version-
   CiscoSecure Email And Web Manager M390 Version-
   CiscoSecure Email And Web Manager M390x Version-
   CiscoSecure Email And Web Manager M395 Version-
   CiscoSecure Email And Web Manager M680 Version-
   CiscoSecure Email And Web Manager M690 Version-
   CiscoSecure Email And Web Manager M690x Version-
   CiscoSecure Email And Web Manager M695 Version-
CiscoAsyncos Version14.2.0-620
   CiscoSecure Email And Web Manager Virtual Appliance M100v Version-
   CiscoSecure Email And Web Manager Virtual Appliance M300v Version-
   CiscoSecure Email And Web Manager Virtual Appliance M600v Version-
   CiscoSecure Email And Web Manager M170 Version-
   CiscoSecure Email And Web Manager M190 Version-
   CiscoSecure Email And Web Manager M195 Version-
   CiscoSecure Email And Web Manager M380 Version-
   CiscoSecure Email And Web Manager M390 Version-
   CiscoSecure Email And Web Manager M390x Version-
   CiscoSecure Email And Web Manager M395 Version-
   CiscoSecure Email And Web Manager M680 Version-
   CiscoSecure Email And Web Manager M690 Version-
   CiscoSecure Email And Web Manager M690x Version-
   CiscoSecure Email And Web Manager M695 Version-
CiscoAsyncos Version14.2.1-020
   CiscoSecure Email And Web Manager Virtual Appliance M100v Version-
   CiscoSecure Email And Web Manager Virtual Appliance M300v Version-
   CiscoSecure Email And Web Manager Virtual Appliance M600v Version-
   CiscoSecure Email And Web Manager M170 Version-
   CiscoSecure Email And Web Manager M190 Version-
   CiscoSecure Email And Web Manager M195 Version-
   CiscoSecure Email And Web Manager M380 Version-
   CiscoSecure Email And Web Manager M390 Version-
   CiscoSecure Email And Web Manager M390x Version-
   CiscoSecure Email And Web Manager M395 Version-
   CiscoSecure Email And Web Manager M680 Version-
   CiscoSecure Email And Web Manager M690 Version-
   CiscoSecure Email And Web Manager M690x Version-
   CiscoSecure Email And Web Manager M695 Version-
CiscoAsyncos Version14.3.0-032
   CiscoSecure Email And Web Manager Virtual Appliance M100v Version-
   CiscoSecure Email And Web Manager Virtual Appliance M300v Version-
   CiscoSecure Email And Web Manager Virtual Appliance M600v Version-
   CiscoSecure Email And Web Manager M170 Version-
   CiscoSecure Email And Web Manager M190 Version-
   CiscoSecure Email And Web Manager M195 Version-
   CiscoSecure Email And Web Manager M380 Version-
   CiscoSecure Email And Web Manager M390 Version-
   CiscoSecure Email And Web Manager M390x Version-
   CiscoSecure Email And Web Manager M395 Version-
   CiscoSecure Email And Web Manager M680 Version-
   CiscoSecure Email And Web Manager M690 Version-
   CiscoSecure Email And Web Manager M690x Version-
   CiscoSecure Email And Web Manager M695 Version-
CiscoAsyncos Version15.0.0-104
   CiscoSecure Email And Web Manager Virtual Appliance M100v Version-
   CiscoSecure Email And Web Manager Virtual Appliance M300v Version-
   CiscoSecure Email And Web Manager Virtual Appliance M600v Version-
   CiscoSecure Email And Web Manager M170 Version-
   CiscoSecure Email And Web Manager M190 Version-
   CiscoSecure Email And Web Manager M195 Version-
   CiscoSecure Email And Web Manager M380 Version-
   CiscoSecure Email And Web Manager M390 Version-
   CiscoSecure Email And Web Manager M390x Version-
   CiscoSecure Email And Web Manager M395 Version-
   CiscoSecure Email And Web Manager M680 Version-
   CiscoSecure Email And Web Manager M690 Version-
   CiscoSecure Email And Web Manager M690x Version-
   CiscoSecure Email And Web Manager M695 Version-
CiscoAsyncos Version15.0.1-030
   CiscoSecure Email And Web Manager Virtual Appliance M100v Version-
   CiscoSecure Email And Web Manager Virtual Appliance M300v Version-
   CiscoSecure Email And Web Manager Virtual Appliance M600v Version-
   CiscoSecure Email And Web Manager M170 Version-
   CiscoSecure Email And Web Manager M190 Version-
   CiscoSecure Email And Web Manager M195 Version-
   CiscoSecure Email And Web Manager M380 Version-
   CiscoSecure Email And Web Manager M390 Version-
   CiscoSecure Email And Web Manager M390x Version-
   CiscoSecure Email And Web Manager M395 Version-
   CiscoSecure Email And Web Manager M680 Version-
   CiscoSecure Email And Web Manager M690 Version-
   CiscoSecure Email And Web Manager M690x Version-
   CiscoSecure Email And Web Manager M695 Version-
CiscoAsyncos Version15.0.3-002
   CiscoSecure Email And Web Manager Virtual Appliance M100v Version-
   CiscoSecure Email And Web Manager Virtual Appliance M300v Version-
   CiscoSecure Email And Web Manager Virtual Appliance M600v Version-
   CiscoSecure Email And Web Manager M170 Version-
   CiscoSecure Email And Web Manager M190 Version-
   CiscoSecure Email And Web Manager M195 Version-
   CiscoSecure Email And Web Manager M380 Version-
   CiscoSecure Email And Web Manager M390 Version-
   CiscoSecure Email And Web Manager M390x Version-
   CiscoSecure Email And Web Manager M395 Version-
   CiscoSecure Email And Web Manager M680 Version-
   CiscoSecure Email And Web Manager M690 Version-
   CiscoSecure Email And Web Manager M690x Version-
   CiscoSecure Email And Web Manager M695 Version-
CiscoAsyncos Version15.5.0-048
   CiscoSecure Email And Web Manager Virtual Appliance M100v Version-
   CiscoSecure Email And Web Manager Virtual Appliance M300v Version-
   CiscoSecure Email And Web Manager Virtual Appliance M600v Version-
   CiscoSecure Email And Web Manager M170 Version-
   CiscoSecure Email And Web Manager M190 Version-
   CiscoSecure Email And Web Manager M195 Version-
   CiscoSecure Email And Web Manager M380 Version-
   CiscoSecure Email And Web Manager M390 Version-
   CiscoSecure Email And Web Manager M390x Version-
   CiscoSecure Email And Web Manager M395 Version-
   CiscoSecure Email And Web Manager M680 Version-
   CiscoSecure Email And Web Manager M690 Version-
   CiscoSecure Email And Web Manager M690x Version-
   CiscoSecure Email And Web Manager M695 Version-
CiscoAsyncos Version15.5.1-055
   CiscoSecure Email And Web Manager Virtual Appliance M100v Version-
   CiscoSecure Email And Web Manager Virtual Appliance M300v Version-
   CiscoSecure Email And Web Manager Virtual Appliance M600v Version-
   CiscoSecure Email And Web Manager M170 Version-
   CiscoSecure Email And Web Manager M190 Version-
   CiscoSecure Email And Web Manager M195 Version-
   CiscoSecure Email And Web Manager M380 Version-
   CiscoSecure Email And Web Manager M390 Version-
   CiscoSecure Email And Web Manager M390x Version-
   CiscoSecure Email And Web Manager M395 Version-
   CiscoSecure Email And Web Manager M680 Version-
   CiscoSecure Email And Web Manager M690 Version-
   CiscoSecure Email And Web Manager M690x Version-
   CiscoSecure Email And Web Manager M695 Version-
CiscoAsyncos Version15.5.2-018
   CiscoSecure Email And Web Manager Virtual Appliance M100v Version-
   CiscoSecure Email And Web Manager Virtual Appliance M300v Version-
   CiscoSecure Email And Web Manager Virtual Appliance M600v Version-
   CiscoSecure Email And Web Manager M170 Version-
   CiscoSecure Email And Web Manager M190 Version-
   CiscoSecure Email And Web Manager M195 Version-
   CiscoSecure Email And Web Manager M380 Version-
   CiscoSecure Email And Web Manager M390 Version-
   CiscoSecure Email And Web Manager M390x Version-
   CiscoSecure Email And Web Manager M395 Version-
   CiscoSecure Email And Web Manager M680 Version-
   CiscoSecure Email And Web Manager M690 Version-
   CiscoSecure Email And Web Manager M690x Version-
   CiscoSecure Email And Web Manager M695 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.02% 0.037
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
psirt@cisco.com 3.4 0.8 2.5
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
CWE-250 Execution with Unnecessary Privileges

The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.