Cisco Asyncos vulnerabilities
49 known vulnerabilities affecting cisco/asyncos.
Total CVEs
49
CISA KEV
1
actively exploited
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH20MEDIUM28
Vulnerabilities
Page 2 of 3
CVE-2021-1425P3MEDIUMCVSS 6.5fixed in 13.8.02024-11-18
CVE-2021-1425 [MEDIUM] CWE-201 CVE-2021-1425: A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco
A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Content Security Management Appliance (SMA) could allow an authenticated, remote attacker to access sensitive information on an affected device.
The vulnerability exists because confidential information is being included in HTTP requests that are exchanged betwee
nvd
CVE-2022-20867P3MEDIUMCVSS 6.5≥ 13.0, < 14.2.1≥ 12.0, < 14.2.02022-11-04
CVE-2022-20867 [MEDIUM] CWE-89 CVE-2022-20867: A vulnerability in web-based management interface of the of Cisco Email Security Appliance and Cisco
A vulnerability in web-based management interface of the of Cisco Email Security Appliance and Cisco Secure Email and Web Manager could allow an authenticated, remote attacker to conduct SQL injection attacks as root on an affected system. The attacker must have the credentials of a high-privileged user account.
This vulnerability is due to improper
nvd
CVE-2022-20942P3MEDIUMCVSS 6.5fixed in 14.2.1-015≥ 14.3.0, < 14.3.0-023+5 more2022-11-04
CVE-2022-20942 [MEDIUM] CWE-359 CVE-2022-20942: A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA), Cisco
A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA), Cisco Secure Email and Web Manager, and Cisco Secure Web Appliance, formerly known as Cisco Web Security Appliance (WSA), could allow an authenticated, remote attacker to retrieve sensitive information from an affected device, including user credentials.
T
nvd
CVE-2020-3547P3MEDIUMCVSS 6.5≤ 13.5.1-277≤ 13.6.1-193+1 more2020-09-04
CVE-2020-3547 [MEDIUM] CWE-200 CVE-2020-3547: A vulnerability in the web-based management interface of Cisco AsyncOS software for Cisco Email Secu
A vulnerability in the web-based management interface of Cisco AsyncOS software for Cisco Email Security Appliance (ESA), Cisco Content Security Management Appliance (SMA), and Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to access sensitive information on an affected device. The vulnerability exists because an inse
nvd
CVE-2018-0087P3MEDIUMCVSS 5.6v10.5.1-2962018-03-08
CVE-2018-0087 [MEDIUM] CWE-287 CVE-2018-0087: A vulnerability in the FTP server of the Cisco Web Security Appliance (WSA) could allow an unauthent
A vulnerability in the FTP server of the Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to log in to the FTP server of the device without a valid password. The attacker does need to have a valid username. The vulnerability is due to incorrect FTP user credential validation. An attacker could exploit this vulnerabili
nvd
CVE-2025-20185P3MEDIUMCVSS 6.7v13.0.0-392v13.0.5-007+12 more2025-02-05
CVE-2025-20185 [MEDIUM] CWE-250 CVE-2025-20185: A vulnerability in the implementation of the remote access functionality of Cisco AsyncOS Software f
A vulnerability in the implementation of the remote access functionality of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, Cisco Secure Email Gateway, and Cisco Secure Web Appliance could allow an authenticated, local attacker to elevate privileges to root. The attacker must authenticate with valid administrator credentials.
This vu
nvd
CVE-2019-1884P3MEDIUMCVSS 6.5≥ 10.1, < 10.5.5-005≥ 11.5, < 11.5.2-020+1 more2019-07-04
CVE-2019-1884 [MEDIUM] CWE-20 CVE-2019-1884: A vulnerability in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appl
A vulnerability in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient input validation mechanisms for certain fields in HTTP/HTTPS requests sent through an a
nvd
CVE-2020-3368P4MEDIUMCVSS 5.8fixed in 13.5.02020-06-18
CVE-2020-3368 [MEDIUM] CWE-20 CVE-2020-3368: A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Secu
A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the URL reputation filters on an affected device. The vulnerability is due to insufficient input validation of URLs. An attacker could exploit this vulnerability by crafting t
nvd
CVE-2020-3568P4MEDIUMCVSS 5.8≤ 13.5.22020-10-08
CVE-2020-3568 [MEDIUM] CWE-20 CVE-2020-3568: A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Secu
A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the URL reputation filters on an affected device. The vulnerability is due to insufficient input validation of URLs. An attacker could exploit this vulnerability by crafting a
nvd
CVE-2017-12303P4MEDIUMCVSS 5.3v10.1.1-234v10.1.1-2352017-11-16
CVE-2017-12303 [MEDIUM] CWE-358 CVE-2017-12303: A vulnerability in the Advanced Malware Protection (AMP) file filtering feature of Cisco AsyncOS Sof
A vulnerability in the Advanced Malware Protection (AMP) file filtering feature of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to bypass a configured AMP file filtering rule. The file types affected are zipped or archived file types. The vulnerability is due to incorrect and different
nvd
CVE-2020-26082P4MEDIUMCVSS 5.3fixed in 13.5.22023-08-04
CVE-2020-26082 [MEDIUM] CWE-20 CVE-2020-26082: A vulnerability in the zip decompression engine of Cisco AsyncOS Software for Cisco Email Security A
A vulnerability in the zip decompression engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass content filters that are configured on an affected device.
The vulnerability is due to improper handling of password-protected zip files. An attacker could exploit this vulnerabil
nvd
CVE-2025-20183P4MEDIUMCVSS 5.3v11.8.0-414v11.8.0-429+49 more2025-02-05
CVE-2025-20183 [MEDIUM] CWE-20 CVE-2025-20183: A vulnerability in a policy-based Cisco Application Visibility and Control (AVC) implementation of C
A vulnerability in a policy-based Cisco Application Visibility and Control (AVC) implementation of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to evade the antivirus scanner and download a malicious file onto an endpoint.
The vulnerability is due to improper handling of a crafted range reques
nvd
CVE-2024-20392P4MEDIUMCVSS 6.1v11.0.3-238v11.1.0-069+19 more2024-05-15
CVE-2024-20392 [MEDIUM] CWE-113 CVE-2024-20392: A vulnerability in the web-based management API of Cisco AsyncOS Software for Cisco Secure Email Gat
A vulnerability in the web-based management API of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack.
This vulnerability is due to insufficient input validation of some parameters that are passed to the web-based management API of the affected system. An
nvd
CVE-2021-1534P4MEDIUMCVSS 5.3fixed in 14.0.12021-10-06
CVE-2021-1534 [MEDIUM] CWE-20 CVE-2021-1534: A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Secu
A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the URL reputation filters on an affected device. This vulnerability is due to improper processing of URLs. An attacker could exploit this vulnerability by crafting a URL in a
nvd
CVE-2022-20952P4MEDIUMCVSS 5.3≥ 11.8, < 14.0.4v14.5.02023-03-01
CVE-2022-20952 [MEDIUM] CWE-20 CVE-2022-20952: A vulnerability in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance, fo
A vulnerability in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance, formerly known as Cisco Web Security Appliance (WSA), could allow an unauthenticated, remote attacker to bypass a configured rule, thereby allowing traffic onto a network that should have been blocked.
This vulnerability exists because malformed, encoded
nvd
CVE-2024-20258P4MEDIUMCVSS 6.1fixed in 15.0.2-034≥ 15.5, < 15.5.1-055+1 more2024-05-15
CVE-2024-20258 [MEDIUM] CWE-79 CVE-2024-20258: A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Ema
A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Email Gateway could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of the interface.
This vulnerability is due to insufficient validation of user input. An attacker could exploit this vul
nvd
CVE-2020-3546P4MEDIUMCVSS 5.3≤ 13.5.12020-09-04
CVE-2020-3546 [MEDIUM] CWE-20 CVE-2020-3546: A vulnerability in the web-based management interface of Cisco AsyncOS software for Cisco Email Secu
A vulnerability in the web-based management interface of Cisco AsyncOS software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to access sensitive information on an affected device. The vulnerability is due to insufficient validation of requests that are sent to the web-based management interface. An attacker c
nvd
CVE-2023-20215P4MEDIUMCVSS 5.3v11.7.0-406v11.7.0-418+20 more2023-08-03
CVE-2023-20215 [MEDIUM] CWE-202 CVE-2023-20215: A vulnerability in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance cou
A vulnerability in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to bypass a configured rule, allowing traffic onto a network that should have been blocked.
This vulnerability is due to improper detection of malicious traffic when the traffic is encoded with a specific c
nvd
CVE-2019-1983P4MEDIUMCVSS 5.3fixed in 11.0.1-161≥ 12.0, ≤ 12.5.0-633+2 more2020-09-23
CVE-2019-1983 [MEDIUM] CWE-20 CVE-2019-1983: A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Sec
A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) and Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to cause repeated crashes in some internal processes that are running on the affected devices, resulting in a denial of service (D
nvd
CVE-2022-20675P4MEDIUMCVSS 5.3≥ 14.0, < 14.02.0-020≥ 12.5, < 14.1.0-239+1 more2022-04-06
CVE-2022-20675 [MEDIUM] CWE-248 CVE-2022-20675: A vulnerability in the TCP/IP stack of Cisco Email Security Appliance (ESA), Cisco Web Security Appl
A vulnerability in the TCP/IP stack of Cisco Email Security Appliance (ESA), Cisco Web Security Appliance (WSA), and Cisco Secure Email and Web Manager, formerly Security Management Appliance, could allow an unauthenticated, remote attacker to crash the Simple Network Management Protocol (SNMP) service, resulting in a denial of service (DoS) conditi
nvd