Cisco Secure Email And Web Manager vulnerabilities
16 known vulnerabilities affecting cisco/cisco_secure_email_and_web_manager.
Total CVEs
16
CISA KEV
1
actively exploited
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH3MEDIUM12
Vulnerabilities
Page 1 of 1
CVE-2025-20393CRITICALCVSS 10.0KEVv13.6.2-023v13.6.2-078+24 more2025-12-17
CVE-2025-20393 [CRITICAL] CWE-20 CVE-2025-20393: A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gate
A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to execute arbitrary system commands on an affected device with root privileges.
This vulnerability is due to insufficient validation of HTTP requests by the
cvelistv5nvd
CVE-2020-3122MEDIUMCVSS 5.3v11.0.0(Ritz)-1282025-03-04
CVE-2020-3122 [MEDIUM] CWE-284 CVE-2020-3122: A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Content Security Ma
A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to obtain sensitive network information.
cvelistv5nvd
CVE-2025-20207MEDIUMCVSS 4.3v13.6.2-023v13.6.2-078+18 more2025-02-05
CVE-2025-20207 [MEDIUM] CWE-200 CVE-2025-20207: A vulnerability in Simple Network Management Protocol (SNMP) polling for Cisco Secure Email and Web
A vulnerability in Simple Network Management Protocol (SNMP) polling for Cisco Secure Email and Web Manager, Cisco Secure Email Gateway, and Cisco Secure Web Appliance could allow an authenticated, remote attacker to obtain confidential information about the underlying operating system.
This vulnerability exists because the appliances do not protect
cvelistv5nvd
CVE-2025-20180MEDIUMCVSS 4.8v13.6.2-023v13.6.2-078+20 more2025-02-05
CVE-2025-20180 [MEDIUM] CWE-79 CVE-2025-20180: A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Ema
A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Email Gateway could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface.
This vulnerability is due to insufficient validation of user input. An att
cvelistv5nvd
CVE-2025-20185MEDIUMCVSS 6.7v13.6.2-023v13.6.2-078+19 more2025-02-05
CVE-2025-20185 [LOW] CWE-250 CVE-2025-20185: A vulnerability in the implementation of the remote access functionality of Cisco AsyncOS Software f
A vulnerability in the implementation of the remote access functionality of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, Cisco Secure Email Gateway, and Cisco Secure Web Appliance could allow an authenticated, local attacker to elevate privileges to root. The attacker must authenticate with valid administrator credentials.
This vulne
cvelistv5nvd
CVE-2021-1425MEDIUMCVSS 6.5vN/A2024-11-18
CVE-2021-1425 [MEDIUM] CWE-201 CVE-2021-1425: A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco
A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Content Security Management Appliance (SMA) could allow an authenticated, remote attacker to access sensitive information on an affected device.
The vulnerability exists because confidential information is being included in HTTP requests that are exchanged betwee
cvelistv5nvd
CVE-2024-20504MEDIUMCVSS 5.4v14.0.0-404v14.1.0-223+8 more2024-11-06
CVE-2024-20504 [MEDIUM] CWE-80 CVE-2024-20504: A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Ema
A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, Secure Email Gateway, and Secure Web Appliance could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface.
This vulnerability is due to insufficient validatio
cvelistv5nvd
CVE-2024-20383HIGHCVSS 8.4v13.6.2-078v13.0.0-277+11 more2024-05-15
CVE-2024-20383 [MEDIUM] CWE-79 CVE-2024-20383: A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Ema
A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface.
This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a
cvelistv5nvd
CVE-2024-20256MEDIUMCVSS 4.8v9.0.0-087v11.0.0-115+23 more2024-05-15
CVE-2024-20256 [MEDIUM] CWE-79 CVE-2024-20256: A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Ema
A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Web Appliance could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface.
This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulne
cvelistv5nvd
CVE-2024-20258MEDIUMCVSS 6.1v9.0.0-087v11.0.0-115+23 more2024-05-15
CVE-2024-20258 [MEDIUM] CWE-79 CVE-2024-20258: A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Ema
A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Email Gateway could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of the interface.
This vulnerability is due to insufficient validation of user input. An attacker could exploit this vul
cvelistv5nvd
CVE-2023-20119MEDIUMCVSS 6.1v11.0.0-115v11.0.1-161+21 more2023-06-28
CVE-2023-20119 [MEDIUM] CWE-79 CVE-2023-20119: A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Ema
A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, formerly known as Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.
This vulnerability is due to insufficient
cvelistv5nvd
CVE-2023-20009HIGHCVSS 7.2v11.0.0-115v11.0.1-161+16 more2023-03-01
CVE-2023-20009 [MEDIUM] CWE-20 CVE-2023-20009: A vulnerability in the Web UI and administrative CLI of the Cisco Secure Email Gateway (ESA) and Cis
A vulnerability in the Web UI and administrative CLI of the Cisco Secure Email Gateway (ESA) and Cisco Secure Email and Web Manager (SMA) could allow an authenticated remote attacker and or authenticated local attacker to escalate their privilege level and gain root access. The attacker has to have a valid user credential with at least a [[privilege
cvelistv5nvd
CVE-2022-20868HIGHCVSS 8.8v12.0.0-452v12.0.1-011+12 more2022-11-04
CVE-2022-20868 [MEDIUM] CWE-321 CVE-2022-20868: A vulnerability in the web-based management interface of Cisco Email Security Appliance, Cisco Secur
A vulnerability in the web-based management interface of Cisco Email Security Appliance, Cisco Secure Email and Web Manager and Cisco Secure Web Appliance could allow an authenticated, remote attacker to elevate privileges on an affected system. The attacker needs valid credentials to exploit this vulnerability.
This vulnerability is due to the use
cvelistv5nvd
CVE-2022-20867MEDIUMCVSS 6.5v12.0.1-011v12.5.0-636+11 more2022-11-04
CVE-2022-20867 [MEDIUM] CWE-89 CVE-2022-20867: A vulnerability in web-based management interface of the of Cisco Email Security Appliance and Cisco
A vulnerability in web-based management interface of the of Cisco Email Security Appliance and Cisco Secure Email and Web Manager could allow an authenticated, remote attacker to conduct SQL injection attacks as root on an affected system. The attacker must have the credentials of a high-privileged user account.
This vulnerability is due to improper
cvelistv5nvd
CVE-2022-20942MEDIUMCVSS 6.5v11.0.0-115v11.0.1-161+16 more2022-11-04
CVE-2022-20942 [MEDIUM] CWE-359 CVE-2022-20942: A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA), Cisco
A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA), Cisco Secure Email and Web Manager, and Cisco Secure Web Appliance, formerly known as Cisco Web Security Appliance (WSA), could allow an authenticated, remote attacker to retrieve sensitive information from an affected device, including user credentials.
T
cvelistv5nvd
CVE-2022-20772MEDIUMCVSS 5.3v14.0.0-404v14.1.0-223+2 more2022-11-04
CVE-2022-20772 [MEDIUM] CWE-113 CVE-2022-20772: A vulnerability in Cisco Email Security Appliance (ESA) and Cisco Secure Email and Web Manager could
A vulnerability in Cisco Email Security Appliance (ESA) and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack.
This vulnerability is due to the failure of the application or its environment to properly sanitize input values. An attacker could exploit this vulnerability by
cvelistv5nvd