CVE-2025-20184

A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Web Appliance could allow an authenticated, remote attacker to perform command injection attacks against an affected device. The attacker must authenticate with valid administrator credentials.

This vulnerability is due to insufficient validation of XML configuration files by an affected device. An attacker could exploit this vulnerability by uploading a crafted XML configuration file. A successful exploit could allow the attacker to inject commands to the underlying operating system with root privileges.
Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
ciscoCNA
6.5 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 32%
VendorProductVersion
ciscoasyncos
13.0.0-392
ciscoasyncos
13.0.5-007
ciscoasyncos
13.5.1-277
ciscoasyncos
13.5.4-038
ciscoasyncos
14.0.0-698
ciscoasyncos
14.2.0-620
ciscoasyncos
14.2.1-020
ciscoasyncos
14.3.0-032
ciscoasyncos
15.0.0-104
ciscoasyncos
15.0.1-030
ciscoasyncos
15.0.3-002
ciscoasyncos
15.5.0-048
ciscoasyncos
15.5.1-055
ciscoasyncos
15.5.2-018
ciscoasyncos
15.5.3-022
ciscoasyncos
11.8.0-414
ciscoasyncos
11.8.0-429
ciscoasyncos
11.8.0-453
ciscoasyncos
11.8.1-023
ciscoasyncos
11.8.3-018
ciscoasyncos
11.8.3-021
ciscoasyncos
11.8.4-004
ciscoasyncos
12.0.1-268
ciscoasyncos
12.0.1-334
ciscoasyncos
12.0.2-004
ciscoasyncos
12.0.2-012
ciscoasyncos
12.0.3-005
ciscoasyncos
12.0.3-007
ciscoasyncos
12.0.4-002
ciscoasyncos
12.0.5-011
ciscoasyncos
12.5.1-011
ciscoasyncos
12.5.1-043
ciscoasyncos
12.5.2-007
ciscoasyncos
12.5.2-011
ciscoasyncos
12.5.3-002
ciscoasyncos
12.5.4-005
ciscoasyncos
12.5.4-011
ciscoasyncos
12.5.5-004
ciscoasyncos
12.5.5-005
ciscoasyncos
12.5.5-008
ciscoasyncos
12.5.6-008
ciscoasyncos
14.0.1-014
ciscoasyncos
14.0.1-040
ciscoasyncos
14.0.1-053
ciscoasyncos
14.0.1-503
ciscoasyncos
14.0.2-012
ciscoasyncos
14.0.3-014
ciscoasyncos
14.0.4-005
ciscoasyncos
14.0.5-007
ciscoasyncos
14.1.0-032
ciscoasyncos
14.1.0-041
ciscoasyncos
14.1.0-047
ciscoasyncos
14.5.0-498
ciscoasyncos
14.5.0-537
ciscoasyncos
14.5.0-673
ciscoasyncos
14.5.1-008
ciscoasyncos
14.5.1-016
ciscoasyncos
14.5.1-510
ciscoasyncos
14.5.1-607
ciscoasyncos
14.5.2-011
ciscoasyncos
14.5.3-033
ciscoasyncos
15.0.0-322
ciscoasyncos
15.0.0-355
ciscoasyncos
15.0.1-004
ciscoasyncos
15.1.0-287
ciscoasyncos
15.2.0-116
ciscoasyncos
15.2.0-164
ciscoasyncos
15.2.1-011
𝑥
= Vulnerable software versions