Cisco Secure Email vulnerabilities
28 known vulnerabilities affecting cisco/cisco_secure_email.
Total CVEs
28
CISA KEV
2
actively exploited
Public exploits
0
Exploited in wild
2
Severity breakdown
CRITICAL6HIGH7MEDIUM15
Vulnerabilities
Page 1 of 2
CVE-2025-20393P1CRITICALCVSS 10.0KEVv14.0.0-698v13.5.1-277+16 more2025-12-17
CVE-2025-20393 [CRITICAL] CWE-20 CVE-2025-20393: A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gate
A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to execute arbitrary system commands on an affected device with root privileges.
This vulnerability is due to insufficient validation of HTTP requests by the
nvd
CVE-2026-76461P1CRITICALCVSS 9.8KEVv14.0.0-698v13.5.1-277+21 more2026-09-14
CVE-2026-76461 [CRITICAL] CWE-89 CVE-2026-76461: A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could
A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.
This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerabi
nvd
CVE-2024-20401P2CRITICALCVSS 9.8vN/A2024-07-17
CVE-2024-20401 [CRITICAL] CWE-36 CVE-2024-20401: A vulnerability in the content scanning and message filtering features of Cisco Secure Email Gateway
A vulnerability in the content scanning and message filtering features of Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to overwrite arbitrary files on the underlying operating system.
This vulnerability is due to improper handling of email attachments when file analysis and content filters are enabled. An attacker coul
nvd
CVE-2026-20353P2CRITICALCVSS 9.8v14.0.0-698v13.5.1-277+21 more2026-09-14
CVE-2026-20353 [CRITICAL] CWE-664 CVE-2026-20353: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Em
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.
The vulnera
nvd
CVE-2026-76440P2CRITICALCVSS 9.8v14.0.0-698v13.5.1-277+22 more2026-09-14
CVE-2026-76440 [CRITICAL] CWE-23 CVE-2026-76440: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Em
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.
The vulnerab
nvd
CVE-2026-76443P3CRITICALCVSS 9.8v14.0.0-698v13.5.1-277+21 more2026-09-14
CVE-2026-76443 [CRITICAL] CWE-707 CVE-2026-76443: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Em
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.
The vulnera
nvd
CVE-2022-20868P3HIGHCVSS 8.8v13.0.0-392v13.5.1-277+2 more2022-11-04
CVE-2022-20868 [HIGH] CWE-321 CVE-2022-20868: A vulnerability in the web-based management interface of Cisco Email Security Appliance, Cisco Secur
A vulnerability in the web-based management interface of Cisco Email Security Appliance, Cisco Secure Email and Web Manager and Cisco Secure Web Appliance could allow an authenticated, remote attacker to elevate privileges on an affected system. The attacker needs valid credentials to exploit this vulnerability.
This vulnerability is due to the use o
nvd
CVE-2025-20184P3HIGHCVSS 7.2v14.0.0-698v13.5.1-277+13 more2025-02-05
CVE-2025-20184 [HIGH] CWE-20 CVE-2025-20184: A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Ema
A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Web Appliance could allow an authenticated, remote attacker to perform command injection attacks against an affected device. The attacker must authenticate with valid administrator credentials.
This vulnerability is due to in
nvd
CVE-2024-20429P3HIGHCVSS 7.2v11.0.3-238v11.1.0-069+16 more2024-07-17
CVE-2024-20429 [HIGH] CWE-74 CVE-2024-20429: A vulnerability in the web-based management interface of Cisco AsyncOS for Secure Email Gateway coul
A vulnerability in the web-based management interface of Cisco AsyncOS for Secure Email Gateway could allow an authenticated, remote attacker to execute arbitrary system commands on an affected device.
This vulnerability is due to insufficient input validation in certain portions of the web-based management interface. An attacker could exploit this vul
nvd
CVE-2023-20009P3HIGHCVSS 7.2v11.0.3-238v11.1.0-069+11 more2023-03-01
CVE-2023-20009 [HIGH] CWE-20 CVE-2023-20009: A vulnerability in the Web UI and administrative CLI of the Cisco Secure Email Gateway (ESA) and Cis
A vulnerability in the Web UI and administrative CLI of the Cisco Secure Email Gateway (ESA) and Cisco Secure Email and Web Manager (SMA) could allow an authenticated remote attacker and or authenticated local attacker to escalate their privilege level and gain root access. The attacker has to have a valid user credential with at least a [[privilege of
nvd
CVE-2026-76442P3HIGHCVSS 7.5v14.0.0-698v13.5.1-277+22 more2026-09-14
CVE-2026-76442 [HIGH] CWE-1284 CVE-2026-76442: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Em
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.
The vulnerabil
nvd
CVE-2020-3548P3HIGHCVSS 7.5vN/A2024-11-18
CVE-2020-3548 [HIGH] CWE-407 CVE-2020-3548: A vulnerability in the Transport Layer Security (TLS) protocol implementation of Cisco AsyncOS
A vulnerability in the Transport Layer Security (TLS) protocol implementation of Cisco AsyncOS software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause high CPU usage on an affected device, resulting in a denial of service (DoS) condition.
The vulnerability is due to inefficient processing of incoming TLS
nvd
CVE-2022-20960P3HIGHCVSS 7.5v11.0.3-238v11.1.0-069+11 more2022-11-04
CVE-2022-20960 [HIGH] CWE-400 CVE-2022-20960: A vulnerability in Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an un
A vulnerability in Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated remote attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to improper handling of certain TLS connections that are processed by an affected device. An attacker could exploit this vulnerab
nvd
CVE-2022-20867P3MEDIUMCVSS 6.5v13.0.0-392v13.5.1-277+3 more2022-11-04
CVE-2022-20867 [MEDIUM] CWE-89 CVE-2022-20867: A vulnerability in web-based management interface of the of Cisco Email Security Appliance and Cisco
A vulnerability in web-based management interface of the of Cisco Email Security Appliance and Cisco Secure Email and Web Manager could allow an authenticated, remote attacker to conduct SQL injection attacks as root on an affected system. The attacker must have the credentials of a high-privileged user account.
This vulnerability is due to improper
nvd
CVE-2022-20942P3MEDIUMCVSS 6.5v11.0.3-238v11.1.0-069+11 more2022-11-04
CVE-2022-20942 [MEDIUM] CWE-359 CVE-2022-20942: A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA), Cisco
A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA), Cisco Secure Email and Web Manager, and Cisco Secure Web Appliance, formerly known as Cisco Web Security Appliance (WSA), could allow an authenticated, remote attacker to retrieve sensitive information from an affected device, including user credentials.
T
nvd
CVE-2023-20075P3MEDIUMCVSS 6.7v13.0.0-392v13.5.1-277+3 more2023-03-01
CVE-2023-20075 [MEDIUM] CWE-77 CVE-2023-20075: Vulnerability in the CLI of Cisco Secure Email Gateway could allow an authenticated, remote attacker
Vulnerability in the CLI of Cisco Secure Email Gateway could allow an authenticated, remote attacker to execute arbitrary commands.
These vulnerability is due to improper input validation in the CLI. An attacker could exploit this vulnerability by injecting operating system commands into a legitimate command. A successful exploit could allow the atta
nvd
CVE-2025-20185P3MEDIUMCVSS 6.7v14.0.0-698v13.5.1-277+12 more2025-02-05
CVE-2025-20185 [MEDIUM] CWE-250 CVE-2025-20185: A vulnerability in the implementation of the remote access functionality of Cisco AsyncOS Software f
A vulnerability in the implementation of the remote access functionality of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, Cisco Secure Email Gateway, and Cisco Secure Web Appliance could allow an authenticated, local attacker to elevate privileges to root. The attacker must authenticate with valid administrator credentials.
This vu
nvd
CVE-2026-20354P3MEDIUMCVSS 5.9v14.0.0-698v13.5.1-277+22 more2026-09-02
CVE-2026-20354 [MEDIUM] CWE-354 CVE-2026-20354: Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption fun
Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages.
These vulnerabilities are due to insufficient validation of message integrity. An attacker could exploit these vulne
nvd
CVE-2026-20355P3MEDIUMCVSS 5.9v14.0.0-698v13.5.1-277+22 more2026-09-02
CVE-2026-20355 [MEDIUM] CWE-345 CVE-2026-20355: Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption fun
Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages.
These vulnerabilities are due to insufficient validation of message integrity. An attacker could exploit these vulne
nvd
CVE-2025-20153P4MEDIUMCVSS 5.3v14.0.0-698v13.5.1-277+13 more2025-02-19
CVE-2025-20153 [MEDIUM] CWE-284 CVE-2025-20153: A vulnerability in the email filtering mechanism of Cisco Secure Email Gateway could allow an unauth
A vulnerability in the email filtering mechanism of Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to bypass the configured rules and allow emails that should have been denied to flow through an affected device.
This vulnerability is due to improper handling of email that passes through an affected device. An attacker co
nvd
1 / 2Next →