CVE-2025-20184

Cisco Secure Email and Web Manager and Secure Web Appliance Command Injection Vulnerability

Severity
Medium 6.5
CVSS 3.1
Remote, needs privileges or user interaction what this means
Exploited
Not listed
EPSS
0.009
57.2th percentile
Discovered by
Third party
Vendor-published field
Published
Feb 5, 2025
Assigned by cisco

Description

A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Web Appliance could allow an authenticated, remote attacker to perform command injection attacks against an affected device. The attacker must authenticate with valid administrator credentials. This vulnerability is due to insufficient validation of XML configuration files by an affected device. An attacker could exploit this vulnerability by uploading a crafted XML configuration file. A successful exploit could allow the attacker to inject commands to the underlying operating system with root privileges.

Weakness: CWE-20

Affected products

Vendor Product Category Matched by
Cisco Cisco Secure Email Gateway Email Security cna-assigner
Cisco Cisco Secure Web Appliance SASE / SSE / Secure Web cna-assigner
Vendor-reported products (2)
  • Cisco · Cisco Secure Email
  • Cisco · Cisco Secure Web Appliance

Vendor advisory

cisco-sa-esa-sma-wsa-multi-yKUJhS34

Cisco Secure Email and Web Manager, Secure Email Gateway, and Secure Web Appliance Vulnerabilities

Cisco’s rating: Medium (advisory CVSS 6.5) · Published Feb 5, 2025 · updated Feb 7, 2025 (revision 1.1)

Bug IDs: CSCwk70547 , CSCwk70559 , CSCwk70574 , CSCwk70576 , CSCwk70590 , CSCwk98506

The vendor’s rating applies to the whole advisory and can differ from this CVE’s own CVSS severity. Where this comes from

Something wrong here?