CVE-2025-20184
Published: Feb 5, 2025
Modified: Feb 5, 2025
CVSS v3.1
6.5
Description
A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Web Appliance could allow an authenticated, remote attacker to perform command injection attacks against an affected device. The attacker must authenticate with valid administrator credentials. This vulnerability is due to insufficient validation of XML configuration files by an affected device. An attacker could exploit this vulnerability by uploading a crafted XML configuration file. A successful exploit could allow the attacker to inject commands to the underlying operating system with root privileges.
| Vendor | Product | Versions |
|---|---|---|
Cisco | Cisco Secure Email | affected 14.0.0-698affected 13.5.1-277affected 13.0.0-392affected 14.2.0-620affected 13.0.5-007+10 more versions |
Cisco | Cisco Secure Web Appliance | affected 11.8.0-453affected 12.5.3-002affected 12.0.3-007affected 12.0.3-005affected 14.1.0-032+48 more versions |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now