10

CVE-2025-20393

Warnung
Medienbericht
A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to execute arbitrary system commands on an affected device with root privileges.

This vulnerability is due to insufficient validation of HTTP requests by the Spam Quarantine feature. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with root privileges.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CiscoAsyncos Version < 15.0.2-007
   CiscoSecure Email And Web Manager Virtual Appliance M100v Version-
   CiscoSecure Email And Web Manager Virtual Appliance M300v Version-
   CiscoSecure Email And Web Manager Virtual Appliance M600v Version-
   CiscoSecure Email And Web Manager M170 Version-
   CiscoSecure Email And Web Manager M190 Version-
   CiscoSecure Email And Web Manager M195 Version-
   CiscoSecure Email And Web Manager M380 Version-
   CiscoSecure Email And Web Manager M390 Version-
   CiscoSecure Email And Web Manager M390x Version-
   CiscoSecure Email And Web Manager M395 Version-
   CiscoSecure Email And Web Manager M680 Version-
   CiscoSecure Email And Web Manager M690 Version-
   CiscoSecure Email And Web Manager M690x Version-
   CiscoSecure Email And Web Manager M695 Version-
CiscoAsyncos Version >= 15.5 < 15.5.4-007
   CiscoSecure Email And Web Manager Virtual Appliance M100v Version-
   CiscoSecure Email And Web Manager Virtual Appliance M300v Version-
   CiscoSecure Email And Web Manager Virtual Appliance M600v Version-
   CiscoSecure Email And Web Manager M170 Version-
   CiscoSecure Email And Web Manager M190 Version-
   CiscoSecure Email And Web Manager M195 Version-
   CiscoSecure Email And Web Manager M380 Version-
   CiscoSecure Email And Web Manager M390 Version-
   CiscoSecure Email And Web Manager M390x Version-
   CiscoSecure Email And Web Manager M395 Version-
   CiscoSecure Email And Web Manager M680 Version-
   CiscoSecure Email And Web Manager M690 Version-
   CiscoSecure Email And Web Manager M690x Version-
   CiscoSecure Email And Web Manager M695 Version-
CiscoAsyncos Version >= 16.0 < 16.0.4-010
   CiscoSecure Email And Web Manager Virtual Appliance M100v Version-
   CiscoSecure Email And Web Manager Virtual Appliance M300v Version-
   CiscoSecure Email And Web Manager Virtual Appliance M600v Version-
   CiscoSecure Email And Web Manager M170 Version-
   CiscoSecure Email And Web Manager M190 Version-
   CiscoSecure Email And Web Manager M195 Version-
   CiscoSecure Email And Web Manager M380 Version-
   CiscoSecure Email And Web Manager M390 Version-
   CiscoSecure Email And Web Manager M390x Version-
   CiscoSecure Email And Web Manager M395 Version-
   CiscoSecure Email And Web Manager M680 Version-
   CiscoSecure Email And Web Manager M690 Version-
   CiscoSecure Email And Web Manager M690x Version-
   CiscoSecure Email And Web Manager M695 Version-

17.12.2025: CISA Known Exploited Vulnerabilities (KEV) Catalog

Cisco Multiple Products Improper Input Validation Vulnerability

Schwachstelle

Cisco Secure Email Gateway, Secure Email, AsyncOS Software, and Web Manager appliances contains an improper input validation vulnerability that allows threat actors to execute arbitrary commands with root privileges on the underlying operating system of an affected appliance.

Beschreibung

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 6.14% 0.906
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
psirt@cisco.com 10 3.9 6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.