Cisco Secure Email Gateway vulnerabilities
5 known vulnerabilities affecting cisco/secure_email_gateway.
Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1MEDIUM4
Vulnerabilities
Page 1 of 1
CVE-2025-20153MEDIUMCVSS 5.3v13.0.0-392v13.0.5-007+13 more2025-02-19
CVE-2025-20153 [MEDIUM] CWE-284 CVE-2025-20153: A vulnerability in the email filtering mechanism of Cisco Secure Email Gateway could allow an unauth
A vulnerability in the email filtering mechanism of Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to bypass the configured rules and allow emails that should have been denied to flow through an affected device.
This vulnerability is due to improper handling of email that passes through an affected device. An attacker co
nvd
CVE-2024-20401CRITICALCVSS 9.8fixed in 15.5.1-0552024-07-17
CVE-2024-20401 [CRITICAL] CWE-36 CVE-2024-20401: A vulnerability in the content scanning and message filtering features of Cisco Secure Email Gateway
A vulnerability in the content scanning and message filtering features of Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to overwrite arbitrary files on the underlying operating system.
This vulnerability is due to improper handling of email attachments when file analysis and content filters are enabled. An attacker coul
nvd
CVE-2023-20120MEDIUMCVSS 6.1v14.0.0-418v14.0.1-033+3 more2023-06-28
CVE-2023-20120 [MEDIUM] CWE-79 CVE-2023-20120: Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco S
Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager; Cisco Secure Email Gateway, formerly Cisco Email Security Appliance (ESA); and Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow a remote attacker to conduct a cross-site scripting (XSS) a
nvd
CVE-2023-20119MEDIUMCVSS 6.1v14.0.0-418v14.0.1-033+3 more2023-06-28
CVE-2023-20119 [MEDIUM] CWE-79 CVE-2023-20119: A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Ema
A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, formerly known as Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.
This vulnerability is due to insufficient
nvd
CVE-2023-20028MEDIUMCVSS 5.4v14.0.0-418v14.0.1-033+3 more2023-06-28
CVE-2023-20028 [MEDIUM] CWE-79 CVE-2023-20028: Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco S
Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager; Cisco Secure Email Gateway, formerly Cisco Email Security Appliance (ESA); and Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow a remote attacker to conduct a cross-site scripting (XSS) a
nvd