CVE-2025-20207
- EPSS 0.07%
- Published 05.02.2025 17:15:26
- Last modified 05.02.2025 17:15:26
A vulnerability in Simple Network Management Protocol (SNMP) polling for Cisco Secure Email and Web Manager, Cisco Secure Email Gateway, and Cisco Secure Web Appliance could allow an authenticated, remote attacker to obtain confidential information a...
CVE-2025-20183
- EPSS 0.11%
- Published 05.02.2025 17:15:25
- Last modified 05.08.2025 19:28:30
A vulnerability in a policy-based Cisco Application Visibility and Control (AVC) implementation of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to evade the antivirus scanner and download a mal...
CVE-2025-20184
- EPSS 0.16%
- Published 05.02.2025 17:15:25
- Last modified 08.08.2025 17:11:23
A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Web Appliance could allow an authenticated, remote attacker to perform command injection attacks against an affected devic...
CVE-2025-20185
- EPSS 0.02%
- Published 05.02.2025 17:15:25
- Last modified 06.08.2025 16:53:52
A vulnerability in the implementation of the remote access functionality of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, Cisco Secure Email Gateway, and Cisco Secure Web Appliance could allow an authenticated, local attacker to elev...
CVE-2022-20871
- EPSS 0.41%
- Published 15.11.2024 16:15:23
- Last modified 11.08.2025 17:44:07
A vulnerability in the web management interface of Cisco AsyncOS for Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow an authenticated, remote attacker to perform a command injection and elevate...
CVE-2024-20504
- EPSS 0.08%
- Published 06.11.2024 17:15:16
- Last modified 07.08.2025 19:08:29
A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, Secure Email Gateway, and Secure Web Appliance could allow an authenticated, remote attacker to conduct a stored cross-site script...
CVE-2024-20435
- EPSS 0.13%
- Published 17.07.2024 17:15:14
- Last modified 08.08.2025 01:55:41
A vulnerability in the CLI of Cisco AsyncOS for Secure Web Appliance could allow an authenticated, local attacker to execute arbitrary commands and elevate privileges to root. This vulnerability is due to insufficient validation of user-supplied i...
CVE-2024-20256
- EPSS 0.13%
- Published 15.05.2024 18:15:08
- Last modified 07.08.2025 17:10:32
A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Web Appliance could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface. ...