CVE-2025-20393 is a critical vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager. This flaw allows unauthenticated, remote attackers to execute arbitrary system commands with root privileges due to insufficient validation of HTTP requests. With a CVSS score of 10.0, it represents a severe risk, enabling complete compromise of affected systems. The vulnerability is actively exploited in the wild, as confirmed by its inclusion in the KEV catalog, and has garnered significant community discussion and media coverage. While no public Metasploit or ExploitDB modules are available, its active exploitation underscores the urgency for immediate patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 15.0.5-016CPE matchmatch criteria | cpe:2.3:o:cisco:asyncos:*:*:*:*:*:*:*:* | ||
>= 15.5, < 15.5.4-012CPE matchmatch criteria | cpe:2.3:o:cisco:asyncos:*:*:*:*:*:*:*:* | ||
>= 16.0, < 16.0.4-016CPE matchmatch criteria | cpe:2.3:o:cisco:asyncos:*:*:*:*:*:*:*:* | ||
< 15.0.2-007CPE matchmatch criteria | cpe:2.3:o:cisco:asyncos:*:*:*:*:*:*:*:* | ||
>= 15.5, < 15.5.4-007CPE matchmatch criteria | cpe:2.3:o:cisco:asyncos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Cisco Multiple AsyncOS Products Integer Overflow (CVE-2025-20393)
Mar 24, 2026Cisco Multiple AsyncOS Products Integer Overflow (CVE-2025-20393)
Mar 24, 2026Cisco Multiple AsyncOS Products Integer Overflow (CVE-2025-20393)
Mar 24, 2026