V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
BDU:2025-16120
BDU
CriticalConfirmedExploit available

Уязвимость функции Spam Quarantine операционной системы Cisco AsyncOS средств защиты Cisco Secure Email and Web Manager, Cisco Secure Email…

CVSS
10.0
Critical
EPSS
0.00
p0
Published
2025-01-01
Updated
2025-01-01
Description

Уязвимость функции Spam Quarantine операционной системы Cisco AsyncOS средств защиты Cisco Secure Email and Web Manager, Cisco Secure Email Gateway связана с недостатками механизма проверки входных данных. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, выполнить произвольный код с правами root

Tags · CWE
Pre-auth
Affected products
Cisco systems inc. Cisco secure email and web managerCisco systems inc. Cisco secure email gatewayCisco systems inc. Secure email and web manager virtual applianceCisco systems inc. Secure email gateway virtual appliance
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Timeline
2025-01-01
Published
2025-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: C
Changed (C)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.000 · p0
Known exploited (KEV)
No
Known exploits — Сканер-ВС
CVE-2025-20393
github-poc · https://github.com/cyberdudebivash/CYBERDUDEBIVASH-Cisco-AsyncOS-CVE-2025-20393-Scanner
Enterprise
Affected products
ProductVendorStatus
cisco secure email and web managercisco systems inc.Tracked
cisco secure email gatewaycisco systems inc.Tracked
secure email and web manager virtual appliancecisco systems inc.Tracked
secure email gateway virtual appliancecisco systems inc.Tracked