CVE-2025-20183

A vulnerability in a policy-based Cisco Application Visibility and Control (AVC) implementation of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to evade the antivirus scanner and download a malicious file onto an endpoint. 

The vulnerability is due to improper handling of a crafted range request header. An attacker could exploit this vulnerability by sending an HTTP request with a crafted range request header through the affected device. A successful exploit could allow the attacker to evade the antivirus scanner and download malware onto the endpoint without detection by Cisco Secure Web Appliance.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.8 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
ciscoCNA
5.8 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 26%
VendorProductVersion
ciscoasyncos
11.8.0-414
ciscoasyncos
11.8.0-429
ciscoasyncos
11.8.0-453
ciscoasyncos
11.8.1-023
ciscoasyncos
11.8.3-018
ciscoasyncos
11.8.3-021
ciscoasyncos
11.8.4-004
ciscoasyncos
12.0.1-268
ciscoasyncos
12.0.1-334
ciscoasyncos
12.0.2-004
ciscoasyncos
12.0.2-012
ciscoasyncos
12.0.3-005
ciscoasyncos
12.0.3-007
ciscoasyncos
12.0.4-002
ciscoasyncos
12.0.5-011
ciscoasyncos
12.5.1-011
ciscoasyncos
12.5.1-043
ciscoasyncos
12.5.2-007
ciscoasyncos
12.5.2-011
ciscoasyncos
12.5.3-002
ciscoasyncos
12.5.4-005
ciscoasyncos
12.5.4-011
ciscoasyncos
12.5.5-004
ciscoasyncos
12.5.5-005
ciscoasyncos
12.5.5-008
ciscoasyncos
12.5.6-008
ciscoasyncos
14.0.1-014
ciscoasyncos
14.0.1-040
ciscoasyncos
14.0.1-053
ciscoasyncos
14.0.1-503
ciscoasyncos
14.0.2-012
ciscoasyncos
14.0.3-014
ciscoasyncos
14.0.4-005
ciscoasyncos
14.0.5-007
ciscoasyncos
14.1.0-032
ciscoasyncos
14.1.0-041
ciscoasyncos
14.1.0-047
ciscoasyncos
14.5.0-498
ciscoasyncos
14.5.0-537
ciscoasyncos
14.5.0-673
ciscoasyncos
14.5.1-008
ciscoasyncos
14.5.1-016
ciscoasyncos
14.5.1-510
ciscoasyncos
14.5.1-607
ciscoasyncos
14.5.2-011
ciscoasyncos
14.5.3-033
ciscoasyncos
15.0.0-322
ciscoasyncos
15.0.0-355
ciscoasyncos
15.1.0-287
ciscoasyncos
15.2.0-116
ciscoasyncos
15.2.0-164
𝑥
= Vulnerable software versions