Cisco Asyncos vulnerabilities
49 known vulnerabilities affecting cisco/asyncos.
Total CVEs
49
CISA KEV
1
actively exploited
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH20MEDIUM28
Vulnerabilities
Page 1 of 3
CVE-2025-20393P1CRITICALCVSS 10.0KEVfixed in 15.0.5-016≥ 15.5, < 15.5.4-012+4 more2025-12-17
CVE-2025-20393 [CRITICAL] CWE-20 CVE-2025-20393: A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gate
A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to execute arbitrary system commands on an affected device with root privileges.
This vulnerability is due to insufficient validation of HTTP requests by the
nvd
CVE-2022-20871P2HIGHCVSS 8.8v12.5.1-011v12.5.2-007+9 more2024-11-15
CVE-2022-20871 [HIGH] CWE-78 CVE-2022-20871: A vulnerability in the web management interface of Cisco AsyncOS for Cisco Secure Web Appl
A vulnerability in the web management interface of Cisco AsyncOS for Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow an authenticated, remote attacker to perform a command injection and elevate privileges to root.
This vulnerability is due to insufficient validation of user-supplied input for the web interface. An a
nvd
CVE-2021-1359P2HIGHCVSS 8.8≥ 11.8.0, < 12.0.3-005≥ 12.5.0, < 12.5.22021-07-08
CVE-2021-1359 [HIGH] CWE-112 CVE-2021-1359: A vulnerability in the configuration management of Cisco AsyncOS for Cisco Web Security Appliance (W
A vulnerability in the configuration management of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to perform command injection and elevate privileges to root. This vulnerability is due to insufficient validation of user-supplied XML input for the web interface. An attacker could exploit this vulnerabil
nvd
CVE-2022-20868P3HIGHCVSS 8.8≥ 13.0, < 14.2.1≥ 12.0, < 14.2.0+3 more2022-11-04
CVE-2022-20868 [HIGH] CWE-321 CVE-2022-20868: A vulnerability in the web-based management interface of Cisco Email Security Appliance, Cisco Secur
A vulnerability in the web-based management interface of Cisco Email Security Appliance, Cisco Secure Email and Web Manager and Cisco Secure Web Appliance could allow an authenticated, remote attacker to elevate privileges on an affected system. The attacker needs valid credentials to exploit this vulnerability.
This vulnerability is due to the use o
nvd
CVE-2019-15956P3HIGHCVSS 8.8≥ 10.1, < 10.1.5-004≥ 10.5, < 11.5.3-016+1 more2019-11-26
CVE-2019-15956 [HIGH] CWE-284 CVE-2019-15956: A vulnerability in the web management interface of Cisco AsyncOS Software for Cisco Web Security App
A vulnerability in the web management interface of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to perform an unauthorized system reset on an affected device. The vulnerability is due to improper authorization controls for a specific URL in the web management interface. An attacker could e
nvd
CVE-2025-20184P3HIGHCVSS 7.2v13.0.0-392v13.0.5-007+66 more2025-02-05
CVE-2025-20184 [HIGH] CWE-20 CVE-2025-20184: A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Ema
A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Web Appliance could allow an authenticated, remote attacker to perform command injection attacks against an affected device. The attacker must authenticate with valid administrator credentials.
This vulnerability is due to in
nvd
CVE-2024-20429P3HIGHCVSS 7.2v11.0.3-238v11.1.0-069+16 more2024-07-17
CVE-2024-20429 [HIGH] CWE-74 CVE-2024-20429: A vulnerability in the web-based management interface of Cisco AsyncOS for Secure Email Gateway coul
A vulnerability in the web-based management interface of Cisco AsyncOS for Secure Email Gateway could allow an authenticated, remote attacker to execute arbitrary system commands on an affected device.
This vulnerability is due to insufficient input validation in certain portions of the web-based management interface. An attacker could exploit this vul
nvd
CVE-2019-1947P3HIGHCVSS 8.6v12.1.0-0852020-09-23
CVE-2019-1947 [HIGH] CWE-20 CVE-2019-1947: A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Sec
A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause the CPU utilization to increase to 100 percent, causing a denial of service (DoS) condition on an affected device. The vulnerability is due to improper handling of email message
nvd
CVE-2019-1886P3HIGHCVSS 8.6≥ 10.5, < 10.5.5-005≥ 11.5, < 11.5.2-0202019-07-04
CVE-2019-1886 [HIGH] CWE-20 CVE-2019-1886: A vulnerability in the HTTPS decryption feature of Cisco Web Security Appliance (WSA) could allow an
A vulnerability in the HTTPS decryption feature of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient validation of Secure Sockets Layer (SSL) server certificates. An attacker could exploit this vulnerability by installing a malformed ce
nvd
CVE-2024-20435P3HIGHCVSS 7.8v11.7.0-406v11.7.0-418+25 more2024-07-17
CVE-2024-20435 [HIGH] CWE-250 CVE-2024-20435: A vulnerability in the CLI of Cisco AsyncOS for Secure Web Appliance could allow an authenticated, l
A vulnerability in the CLI of Cisco AsyncOS for Secure Web Appliance could allow an authenticated, local attacker to execute arbitrary commands and elevate privileges to root.
This vulnerability is due to insufficient validation of user-supplied input for the CLI. An attacker could exploit this vulnerability by authenticating to the system and executi
nvd
CVE-2018-15460P3HIGHCVSS 8.6fixed in 11.0.2-044_md≥ 11.1.0, < 11.1.2-023_md2019-01-10
CVE-2018-15460 [HIGH] CWE-20 CVE-2018-15460: A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Sec
A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) could allow an unauthenticated, remote attacker to cause the CPU utilization to increase to 100 percent, causing a denial of service (DoS) condition on an affected device. The vulnerability is due to improper filtering of email mes
nvd
CVE-2021-1566P3HIGHCVSS 7.4fixed in 12.5.3-035≥ 13.0, < 13.0.0-030+4 more2021-06-16
CVE-2021-1566 [HIGH] CWE-296 CVE-2021-1566: A vulnerability in the Cisco Advanced Malware Protection (AMP) for Endpoints integration of Cisco As
A vulnerability in the Cisco Advanced Malware Protection (AMP) for Endpoints integration of Cisco AsyncOS for Cisco Email Security Appliance (ESA) and Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to intercept traffic between an affected device and the AMP servers. This vulnerability is due to improper certificate va
nvd
CVE-2020-3367P3HIGHCVSS 7.8fixed in 11.7.2-011≥ 11.8.0, < 11.8.2-009+2 more2020-11-18
CVE-2020-3367 [HIGH] CWE-78 CVE-2020-3367: A vulnerability in the log subscription subsystem of Cisco AsyncOS for the Cisco Secure Web Applianc
A vulnerability in the log subscription subsystem of Cisco AsyncOS for the Cisco Secure Web Appliance (formerly Web Security Appliance) could allow an authenticated, local attacker to perform command injection and elevate privileges to root. This vulnerability is due to insufficient validation of user-supplied input for the web interface and CLI. An atta
nvd
CVE-2024-20383P3HIGHCVSS 8.4fixed in 15.5.1-0242024-05-15
CVE-2024-20383 [HIGH] CWE-79 CVE-2024-20383: A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Ema
A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface.
This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a u
nvd
CVE-2016-1461P3HIGHCVSS 7.5≤ 9.7.0-1252016-08-01
CVE-2016-1461 [HIGH] CWE-20 CVE-2016-1461: Cisco AsyncOS on Email Security Appliance (ESA) devices through 9.7.0-125 allows remote attackers to
Cisco AsyncOS on Email Security Appliance (ESA) devices through 9.7.0-125 allows remote attackers to bypass malware detection via a crafted attachment in an e-mail message, aka Bug ID CSCuz14932.
nvd
CVE-2022-20653P3HIGHCVSS 7.5fixed in 13.0.3≥ 13.5.0, < 13.5.4.102+1 more2022-02-17
CVE-2022-20653 [HIGH] CWE-399 CVE-2022-20653: A vulnerability in the DNS-based Authentication of Named Entities (DANE) email verification componen
A vulnerability in the DNS-based Authentication of Named Entities (DANE) email verification component of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient error handling in DNS name
nvd
CVE-2021-34741P3HIGHCVSS 7.5fixed in 13.0.4v13.5.3-010+1 more2021-11-04
CVE-2021-34741 [HIGH] CWE-770 CVE-2021-34741: A vulnerability in the email scanning algorithm of Cisco AsyncOS software for Cisco Email Security A
A vulnerability in the email scanning algorithm of Cisco AsyncOS software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to perform a denial of service (DoS) attack against an affected device. This vulnerability is due to insufficient input validation of incoming emails. An attacker could exploit this vulnerab
nvd
CVE-2021-34698P3HIGHCVSS 7.5≥ 12.0, < 12.0.3-005≥ 12.5, < 12.5.2-007+1 more2021-10-06
CVE-2021-34698 [HIGH] CWE-401 CVE-2021-34698: A vulnerability in the proxy service of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could a
A vulnerability in the proxy service of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to exhaust system memory and cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper memory management in the proxy service of an affected device. An attacker could
nvd
CVE-2016-1438P3HIGHCVSS 7.5v9.7.0-1252016-06-23
CVE-2016-1438 [HIGH] CWE-20 CVE-2016-1438: Cisco AsyncOS 9.7.0-125 on Email Security Appliance (ESA) devices allows remote attackers to bypass
Cisco AsyncOS 9.7.0-125 on Email Security Appliance (ESA) devices allows remote attackers to bypass intended spam filtering via crafted executable content in a ZIP archive, aka Bug ID CSCuy39210.
nvd
CVE-2018-0095P3HIGHCVSS 7.8v9.1.1-005v9.7.2-0652018-01-18
CVE-2018-0095 [HIGH] CWE-264 CVE-2018-0095: A vulnerability in the administrative shell of Cisco AsyncOS on Cisco Email Security Appliance (ESA)
A vulnerability in the administrative shell of Cisco AsyncOS on Cisco Email Security Appliance (ESA) and Content Security Management Appliance (SMA) could allow an authenticated, local attacker to escalate their privilege level and gain root access. The attacker has to have a valid user credential with at least a privilege level of a guest user. The vul
nvd
1 / 3Next →