cbcvebase.
CVE-2025-20183
published 2025-02-05

CVE-2025-20183: A vulnerability in a policy-based Cisco Application Visibility and Control (AVC) implementation of Cisco AsyncOS Software for Cisco Secure Web Appliance could…

PriorityP432medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
0.42%
34.2th percentile
A vulnerability in a policy-based Cisco Application Visibility and Control (AVC) implementation of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to evade the antivirus scanner and download a malicious file onto an endpoint. The vulnerability is due to improper handling of a crafted range request header. An attacker could exploit this vulnerability by sending an HTTP request with a crafted range request header through the affected device. A successful exploit could allow the attacker to evade the antivirus scanner and download malware onto the endpoint without detection by Cisco Secure Web Appliance.

Affected

103 ranges· showing 25
VendorProductVersion rangeFixed in
ciscoasyncos
ciscoasyncos
ciscoasyncos
ciscoasyncos
ciscoasyncos
ciscoasyncos
ciscoasyncos
ciscoasyncos
ciscoasyncos
ciscoasyncos
ciscoasyncos
ciscoasyncos
ciscoasyncos
ciscoasyncos
ciscoasyncos
ciscoasyncos
ciscoasyncos
ciscoasyncos
ciscoasyncos
ciscoasyncos
ciscoasyncos
ciscoasyncos
ciscoasyncos
ciscoasyncos
ciscoasyncos

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
vendor_cisco5.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.