Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-20393

86
FAUCET Score

CVE-2025-20393 is a critical vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager. This flaw allows unauthenticated, remote attackers to execute arbitrary system commands with root privileges due to insufficient validation of HTTP requests. With a CVSS score of 10.0, it represents a severe risk, enabling complete compromise of affected systems. The vulnerability is actively exploited in the wild, as confirmed by its inclusion in the KEV catalog, and has garnered significant community discussion and media coverage. While no public Metasploit or ExploitDB modules are available, its active exploitation underscores the urgency for immediate patching.

Impacted Technologies

VendorProductVersion(s)CPE
< 15.0.5-016CPE matchmatch criteria
cpe:2.3:o:cisco:asyncos:*:*:*:*:*:*:*:*
>= 15.5, < 15.5.4-012CPE matchmatch criteria
cpe:2.3:o:cisco:asyncos:*:*:*:*:*:*:*:*
>= 16.0, < 16.0.4-016CPE matchmatch criteria
cpe:2.3:o:cisco:asyncos:*:*:*:*:*:*:*:*
< 15.0.2-007CPE matchmatch criteria
cpe:2.3:o:cisco:asyncos:*:*:*:*:*:*:*:*
>= 15.5, < 15.5.4-007CPE matchmatch criteria
cpe:2.3:o:cisco:asyncos:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

10.0CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
29.51%
Probability of exploitation in next 30 days
EPSS Percentile
98.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Added to KEV · Dec 17, 2025
This CVE's current EPSS score of 0.2951 is in the 95th percentile among its peer group of 36,862 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (4)

3cxvendor investigatingvia llm_extracted
ciscovendor investigatingvia nvd_reference
View patch
horillavendor investigatingvia llm_extracted
inveniosoftwarevendor investigatingvia llm_extracted

Vendor Advisories (3)

horillallm-horilla-aa91429d93139fb5HIGH

Cisco Multiple AsyncOS Products Integer Overflow (CVE-2025-20393)

Mar 24, 2026
inveniosoftwarellm-inveniosoftware-5384f3fe6490585bHIGH

Cisco Multiple AsyncOS Products Integer Overflow (CVE-2025-20393)

Mar 24, 2026
3cxllm-3cx-85768c7696120996HIGH

Cisco Multiple AsyncOS Products Integer Overflow (CVE-2025-20393)

Mar 24, 2026

References

cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
sec.cloudapps.cisco.com / security/center/content/CiscoSecurityAdvisory/cisco-sa-sma-attack-N9bf4
Vendor Advisory