CVE-2025-20180 describes a stored cross-site scripting (XSS) vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Email Gateway. This medium-severity vulnerability (CVSS 4.8) requires an authenticated, remote attacker with at least Operator-level credentials to persuade a user to click a crafted link. Successful exploitation could lead to arbitrary script execution or access to sensitive browser-based information. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.8.1-002CPE matchmatch criteria | cpe:2.3:o:cisco:asyncos:12.8.1-002:*:*:*:*:*:*:* | ||
12.8.1-021CPE matchmatch criteria | cpe:2.3:o:cisco:asyncos:12.8.1-021:*:*:*:*:*:*:* | ||
13.0.0-249CPE matchmatch criteria | cpe:2.3:o:cisco:asyncos:13.0.0-249:*:*:*:*:*:*:* | ||
13.0.0-277CPE matchmatch criteria | cpe:2.3:o:cisco:asyncos:13.0.0-277:*:*:*:*:*:*:* | ||
13.6.1-201CPE matchmatch criteria | cpe:2.3:o:cisco:asyncos:13.6.1-201:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.