← Back

CVE-2025-20184

nvd nist
Published: Feb 5, 2025Modified: Jun 17, 2026

JSON object

Loading...
7.2
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: NVD

Description

A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Web Appliance could allow an authenticated, remote attacker to perform command injection attacks against an affected device. The attacker must authenticate with valid administrator credentials. This vulnerability is due to insufficient validation of XML configuration files by an affected device. An attacker could exploit this vulnerability by uploading a crafted XML configuration file. A successful exploit could allow the attacker to inject commands to the underlying operating system with root privileges.

Affected (68)

Products: Cisco: Asyncos
1 product
Asyncos
Configuration A
15 vulnerable · 6 platform
Vulnerable SoftwareAffected Versions
Cisco
Version 13.0.0-392
Version 13.0.5-007
Version 13.5.1-277
Version 13.5.4-038
Version 14.0.0-698
Version 14.2.0-620
Version 14.2.1-020
Version 14.3.0-032
Version 15.0.0-104
Version 15.0.1-030
Version 15.0.3-002
Version 15.5.0-048
Version 15.5.1-055
Version 15.5.2-018
Version 15.5.3-022
Running on/withPlatform Versions
Cisco
Secure Email Gateway C195
All versions
Cisco
Secure Email Gateway C395
All versions
Cisco
Secure Email Gateway C695
All versions
Cisco
Secure Email Gateway Virtual Appliance C100v
All versions
Cisco
Secure Email Gateway Virtual Appliance C300v
All versions
Cisco
Secure Email Gateway Virtual Appliance C600v
All versions
Configuration B
53 vulnerable · 7 platform
Vulnerable SoftwareAffected Versions
Cisco
Version 11.8.0-414
Version 11.8.0-429
Version 11.8.0-453
Version 11.8.1-023
Version 11.8.3-018
Version 11.8.3-021
Version 11.8.4-004
Version 12.0.1-268
Version 12.0.1-334
Version 12.0.2-004
Version 12.0.2-012
Version 12.0.3-005
Version 12.0.3-007
Version 12.0.4-002
Version 12.0.5-011
Version 12.5.1-011
Version 12.5.1-043
Version 12.5.2-007
Version 12.5.2-011
Version 12.5.3-002
Version 12.5.4-005
Version 12.5.4-011
Version 12.5.5-004
Version 12.5.5-005
Version 12.5.5-008
Version 12.5.6-008
Version 14.0.1-014
Version 14.0.1-040
Version 14.0.1-053
Version 14.0.1-503
Version 14.0.2-012
Version 14.0.3-014
Version 14.0.4-005
Version 14.0.5-007
Version 14.1.0-032
Version 14.1.0-041
Version 14.1.0-047
Version 14.5.0-498
Version 14.5.0-537
Version 14.5.0-673
Version 14.5.1-008
Version 14.5.1-016
Version 14.5.1-510
Version 14.5.1-607
Version 14.5.2-011
Version 14.5.3-033
Version 15.0.0-322
Version 15.0.0-355
Version 15.0.1-004
Version 15.1.0-287
Version 15.2.0-116
Version 15.2.0-164
Version 15.2.1-011
Running on/withPlatform Versions
Cisco
Secure Web Appliance S196
All versions
Cisco
Secure Web Appliance S396
All versions
Cisco
Secure Web Appliance S696
All versions
Cisco
Secure Web Appliance Virtual S1000v
All versions
Cisco
Secure Web Appliance Virtual S100v
All versions
Cisco
Secure Web Appliance Virtual S300v
All versions
Cisco
Secure Web Appliance Virtual S600v
All versions

Timeline

No history available yet.