CVE-2025-20185
published 2025-02-05CVE-2025-20185: A vulnerability in the implementation of the remote access functionality of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, Cisco Secure Email…
PriorityP336medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.18%
8.0th percentile
A vulnerability in the implementation of the remote access functionality of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, Cisco Secure Email Gateway, and Cisco Secure Web Appliance could allow an authenticated, local attacker to elevate privileges to root. The attacker must authenticate with valid administrator credentials.
This vulnerability is due to an architectural flaw in the password generation algorithm for the remote access functionality. An attacker could exploit this vulnerability by generating a temporary password for the service account. A successful exploit could allow the attacker to execute arbitrary commands as root and access the underlying operating system.
Note: The Security Impact Rating (SIR) for this vulnerability is Medium due to the unrestricted scope of information that is accessible to an attacker.
Affected
103 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | asyncos | — | — |
| cisco | asyncos | — | — |
| cisco | asyncos | — | — |
| cisco | asyncos | — | — |
| cisco | asyncos | — | — |
| cisco | asyncos | — | — |
| cisco | asyncos | — | — |
| cisco | asyncos | — | — |
| cisco | asyncos | — | — |
| cisco | asyncos | — | — |
| cisco | asyncos | — | — |
| cisco | asyncos | — | — |
| cisco | asyncos | — | — |
| cisco | asyncos | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
vendor_cisco6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6wm7-ghvr-4m2g: A vulnerability in the implementation of the remote access functionality of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, Cisco Secur
ghsa_unreviewed·2025-02-05
CVE-2025-20185 [LOW] CWE-250 GHSA-6wm7-ghvr-4m2g: A vulnerability in the implementation of the remote access functionality of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, Cisco Secur
A vulnerability in the implementation of the remote access functionality of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, Cisco Secure Email Gateway, and Cisco Secure Web Appliance could allow an authenticated, local attacker to elevate privileges to root. The attacker must authenticate with valid administrator credentials.
This vulnerability is due to an architectural flaw in the password generation algorithm for the remote access functionality. An attacker could exploit this vulnerability by generating a temporary password for the service account. A successful exploit could allow the attacker to execute arbitrary commands as root and access the underlying operating system.
Note: The Security Impact Rating (SIR) for this vulnerability is Medium due to the unrestricted sc
Cisco
Cisco Secure Email and Web Manager, Secure Email Gateway, and Secure Web Appliance Vulnerabilities
vendor_cisco·2025-02-05·CVSS 6.5
CVE-2025-20184 [MEDIUM] CWE-20 Cisco Secure Email and Web Manager, Secure Email Gateway, and Secure Web Appliance Vulnerabilities
Cisco Secure Email and Web Manager, Secure Email Gateway, and Secure Web Appliance Vulnerabilities
Multiple vulnerabilities in Cisco AsyncOS Software for Cisco Secure Email and Web Manager, Cisco Secure Email Gateway, and Cisco Secure Web Appliance could allow an attacker to execute arbitrary commands locally or remotely.
For more information about these vulnerabilities, see the Details section of this advisory.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-sma-wsa-multi-yKUJhS34
Cisco
Cisco Secure Email and Web Manager, Secure Email Gateway, and Secure Web Appliance Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2025-20185 Cisco Secure Email and Web Manager, Secure Email Gateway, and Secure Web Appliance Vulnerabilities
CVE-2025-20185: Cisco Secure Email and Web Manager, Secure Email Gateway, and Secure Web Appliance Vulnerabilities
Multiple vulnerabilities in Cisco AsyncOS Software for Cisco Secure Email and Web Manager, Cisco Secure Email Gateway, and Cisco Secure Web Appliance could allow an attacker to execute arbitrary commands locally or remotely. For more information about these vulnerabilities, see the
CVSS: 3.1
CWE: CWE-20, CWE-250, CWE-20, CWE-250
Bug IDs: CSCwk70547, CSCwk70559, CSCwk70574, CSCwk70547, CSCwk70559
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-02-05
Published