← Back

CVE-2025-20180

nvd nist
Published: Feb 5, 2025Modified: Aug 15, 2025

JSON object

Loading...
4.8
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Exploitability: 1.7 / Impact: 2.7
Source: psirt@cisco.com (Secondary)

Description

A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Email Gateway could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker must have valid credentials for a user account with at least the role of Operator.

Affected (38)

Products: Cisco: Asyncos
1 product
Asyncos
Configuration A
22 vulnerable · 14 platform
Vulnerable SoftwareAffected Versions
Cisco
Version 12.8.1-002
Version 12.8.1-021
Version 13.0.0-249
Version 13.0.0-277
Version 13.6.1-201
Version 13.6.2-023
Version 13.6.2-078
Version 13.8.1-052
Version 13.8.1-068
Version 13.8.1-074
Version 13.8.1-108
Version 14.0.0-404
Version 14.1.0-227
Version 14.2.0-203
Version 14.2.0-212
Version 14.2.0-224
Version 14.3.0-120
Version 15.0.0-334
Version 15.5.1-024
Version 15.5.1-029
Version 15.5.2-005
Version 16.0.0-195
Running on/withPlatform Versions
Cisco
Secure Email And Web Manager M170
All versions
Cisco
Secure Email And Web Manager M190
All versions
Cisco
Secure Email And Web Manager M195
All versions
Cisco
Secure Email And Web Manager M380
All versions
Cisco
Secure Email And Web Manager M390
All versions
Cisco
Secure Email And Web Manager M390x
All versions
Cisco
Secure Email And Web Manager M395
All versions
Cisco
Secure Email And Web Manager M680
All versions
Cisco
Secure Email And Web Manager M690
All versions
Cisco
Secure Email And Web Manager M690x
All versions
Cisco
Secure Email And Web Manager M695
All versions
Cisco
Secure Email And Web Manager Virtual Appliance M100v
All versions
Cisco
Secure Email And Web Manager Virtual Appliance M300v
All versions
Cisco
Secure Email And Web Manager Virtual Appliance M600v
All versions
Configuration B
16 vulnerable · 6 platform
Vulnerable SoftwareAffected Versions
Cisco
Version 13.0.0-392
Version 13.0.5-007
Version 13.5.1-277
Version 13.5.4-038
Version 14.0.0-698
Version 14.2.0-620
Version 14.2.1-020
Version 14.3.0-032
Version 15.0.0-104
Version 15.0.1-030
Version 15.0.3-002
Version 15.5.0-048
Version 15.5.1-055
Version 15.5.2-018
Version 16.0.0-050
Version 16.0.0-054
Running on/withPlatform Versions
Cisco
Secure Email Gateway C195
All versions
Cisco
Secure Email Gateway C395
All versions
Cisco
Secure Email Gateway C695
All versions
Cisco
Secure Email Gateway Virtual Appliance C100v
All versions
Cisco
Secure Email Gateway Virtual Appliance C300v
All versions
Cisco
Secure Email Gateway Virtual Appliance C600v
All versions

Timeline

No history available yet.