Cisco Secure Email vulnerabilities
21 known vulnerabilities affecting cisco/cisco_secure_email.
Total CVEs
21
CISA KEV
1
actively exploited
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH6MEDIUM13
Vulnerabilities
Page 1 of 2
CVE-2025-20393CRITICALCVSS 10.0KEVv14.0.0-698v13.5.1-277+16 more2025-12-17
CVE-2025-20393 [CRITICAL] CWE-20 CVE-2025-20393: A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gate
A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to execute arbitrary system commands on an affected device with root privileges.
This vulnerability is due to insufficient validation of HTTP requests by the
cvelistv5nvd
CVE-2025-20153MEDIUMCVSS 5.3v14.0.0-698v13.5.1-277+13 more2025-02-19
CVE-2025-20153 [MEDIUM] CWE-284 CVE-2025-20153: A vulnerability in the email filtering mechanism of Cisco Secure Email Gateway could allow an unauth
A vulnerability in the email filtering mechanism of Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to bypass the configured rules and allow emails that should have been denied to flow through an affected device.
This vulnerability is due to improper handling of email that passes through an affected device. An attacker co
cvelistv5nvd
CVE-2025-20184HIGHCVSS 7.2v14.0.0-698v13.5.1-277+13 more2025-02-05
CVE-2025-20184 [MEDIUM] CWE-20 CVE-2025-20184: A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Ema
A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Web Appliance could allow an authenticated, remote attacker to perform command injection attacks against an affected device. The attacker must authenticate with valid administrator credentials.
This vulnerability is due to
cvelistv5nvd
CVE-2025-20207MEDIUMCVSS 4.3v14.0.0-698v13.5.1-277+10 more2025-02-05
CVE-2025-20207 [MEDIUM] CWE-200 CVE-2025-20207: A vulnerability in Simple Network Management Protocol (SNMP) polling for Cisco Secure Email and Web
A vulnerability in Simple Network Management Protocol (SNMP) polling for Cisco Secure Email and Web Manager, Cisco Secure Email Gateway, and Cisco Secure Web Appliance could allow an authenticated, remote attacker to obtain confidential information about the underlying operating system.
This vulnerability exists because the appliances do not protect
cvelistv5nvd
CVE-2025-20180MEDIUMCVSS 4.8v14.0.0-698v13.5.1-277+14 more2025-02-05
CVE-2025-20180 [MEDIUM] CWE-79 CVE-2025-20180: A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Ema
A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Email Gateway could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface.
This vulnerability is due to insufficient validation of user input. An att
cvelistv5nvd
CVE-2025-20185MEDIUMCVSS 6.7v14.0.0-698v13.5.1-277+12 more2025-02-05
CVE-2025-20185 [LOW] CWE-250 CVE-2025-20185: A vulnerability in the implementation of the remote access functionality of Cisco AsyncOS Software f
A vulnerability in the implementation of the remote access functionality of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, Cisco Secure Email Gateway, and Cisco Secure Web Appliance could allow an authenticated, local attacker to elevate privileges to root. The attacker must authenticate with valid administrator credentials.
This vulne
cvelistv5nvd
CVE-2020-3548HIGHCVSS 7.5vN/A2024-11-18
CVE-2020-3548 [MEDIUM] CWE-407 CVE-2020-3548: A vulnerability in the Transport Layer Security (TLS) protocol implementation of Cisco AsyncOS
A vulnerability in the Transport Layer Security (TLS) protocol implementation of Cisco AsyncOS software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause high CPU usage on an affected device, resulting in a denial of service (DoS) condition.
The vulnerability is due to inefficient processing of incoming T
cvelistv5nvd
CVE-2024-20504MEDIUMCVSS 5.4v14.0.0-698v14.2.0-620+6 more2024-11-06
CVE-2024-20504 [MEDIUM] CWE-80 CVE-2024-20504: A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Ema
A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, Secure Email Gateway, and Secure Web Appliance could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface.
This vulnerability is due to insufficient validatio
cvelistv5nvd
CVE-2024-20401CRITICALCVSS 9.8vN/A2024-07-17
CVE-2024-20401 [CRITICAL] CWE-36 CVE-2024-20401: A vulnerability in the content scanning and message filtering features of Cisco Secure Email Gateway
A vulnerability in the content scanning and message filtering features of Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to overwrite arbitrary files on the underlying operating system.
This vulnerability is due to improper handling of email attachments when file analysis and content filters are enabled. An attacker coul
cvelistv5nvd
CVE-2024-20429HIGHCVSS 7.2v11.0.3-238v11.1.0-069+16 more2024-07-17
CVE-2024-20429 [MEDIUM] CWE-74 CVE-2024-20429: A vulnerability in the web-based management interface of Cisco AsyncOS for Secure Email Gateway coul
A vulnerability in the web-based management interface of Cisco AsyncOS for Secure Email Gateway could allow an authenticated, remote attacker to execute arbitrary system commands on an affected device.
This vulnerability is due to insufficient input validation in certain portions of the web-based management interface. An attacker could exploit this v
cvelistv5nvd
CVE-2024-20257MEDIUMCVSS 4.8v11.0.3-238v11.1.0-069+20 more2024-05-15
CVE-2024-20257 [MEDIUM] CWE-79 CVE-2024-20257: A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Ema
A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface.r
This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of
cvelistv5nvd
CVE-2024-20392MEDIUMCVSS 6.1v11.0.3-238v11.1.0-069+19 more2024-05-15
CVE-2024-20392 [MEDIUM] CWE-113 CVE-2024-20392: A vulnerability in the web-based management API of Cisco AsyncOS Software for Cisco Secure Email Gat
A vulnerability in the web-based management API of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack.
This vulnerability is due to insufficient input validation of some parameters that are passed to the web-based management API of the affected system. An
cvelistv5nvd
CVE-2024-20258MEDIUMCVSS 6.1v11.0.3-238v11.1.0-069+20 more2024-05-15
CVE-2024-20258 [MEDIUM] CWE-79 CVE-2024-20258: A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Ema
A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Email Gateway could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of the interface.
This vulnerability is due to insufficient validation of user input. An attacker could exploit this vul
cvelistv5nvd
CVE-2020-26082MEDIUMCVSS 5.3vN/A2023-08-04
CVE-2020-26082 [MEDIUM] CWE-20 CVE-2020-26082: A vulnerability in the zip decompression engine of Cisco AsyncOS Software for Cisco Email Security A
A vulnerability in the zip decompression engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass content filters that are configured on an affected device.
The vulnerability is due to improper handling of password-protected zip files. An attacker could exploit this vulnerabil
cvelistv5nvd
CVE-2023-20009HIGHCVSS 7.2v11.0.3-238v11.1.0-069+11 more2023-03-01
CVE-2023-20009 [MEDIUM] CWE-20 CVE-2023-20009: A vulnerability in the Web UI and administrative CLI of the Cisco Secure Email Gateway (ESA) and Cis
A vulnerability in the Web UI and administrative CLI of the Cisco Secure Email Gateway (ESA) and Cisco Secure Email and Web Manager (SMA) could allow an authenticated remote attacker and or authenticated local attacker to escalate their privilege level and gain root access. The attacker has to have a valid user credential with at least a [[privilege
cvelistv5nvd
CVE-2023-20075MEDIUMCVSS 6.7v13.0.0-392v13.5.1-277+3 more2023-03-01
CVE-2023-20075 [MEDIUM] CWE-77 CVE-2023-20075: Vulnerability in the CLI of Cisco Secure Email Gateway could allow an authenticated, remote attacker
Vulnerability in the CLI of Cisco Secure Email Gateway could allow an authenticated, remote attacker to execute arbitrary commands.
These vulnerability is due to improper input validation in the CLI. An attacker could exploit this vulnerability by injecting operating system commands into a legitimate command. A successful exploit could allow the atta
cvelistv5nvd
CVE-2022-20960HIGHCVSS 7.5v11.0.3-238v11.1.0-069+11 more2022-11-04
CVE-2022-20960 [HIGH] CWE-400 CVE-2022-20960: A vulnerability in Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an un
A vulnerability in Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated remote attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to improper handling of certain TLS connections that are processed by an affected device. An attacker could exploit this vulnerab
cvelistv5nvd
CVE-2022-20868HIGHCVSS 8.8v13.0.0-392v13.5.1-277+2 more2022-11-04
CVE-2022-20868 [MEDIUM] CWE-321 CVE-2022-20868: A vulnerability in the web-based management interface of Cisco Email Security Appliance, Cisco Secur
A vulnerability in the web-based management interface of Cisco Email Security Appliance, Cisco Secure Email and Web Manager and Cisco Secure Web Appliance could allow an authenticated, remote attacker to elevate privileges on an affected system. The attacker needs valid credentials to exploit this vulnerability.
This vulnerability is due to the use
cvelistv5nvd
CVE-2022-20867MEDIUMCVSS 6.5v13.0.0-392v13.5.1-277+3 more2022-11-04
CVE-2022-20867 [MEDIUM] CWE-89 CVE-2022-20867: A vulnerability in web-based management interface of the of Cisco Email Security Appliance and Cisco
A vulnerability in web-based management interface of the of Cisco Email Security Appliance and Cisco Secure Email and Web Manager could allow an authenticated, remote attacker to conduct SQL injection attacks as root on an affected system. The attacker must have the credentials of a high-privileged user account.
This vulnerability is due to improper
cvelistv5nvd
CVE-2022-20942MEDIUMCVSS 6.5v11.0.3-238v11.1.0-069+11 more2022-11-04
CVE-2022-20942 [MEDIUM] CWE-359 CVE-2022-20942: A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA), Cisco
A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA), Cisco Secure Email and Web Manager, and Cisco Secure Web Appliance, formerly known as Cisco Web Security Appliance (WSA), could allow an authenticated, remote attacker to retrieve sensitive information from an affected device, including user credentials.
T
cvelistv5nvd
1 / 2Next →