Asyncos

Vendor:

First CVE: May 20, 2014 · Active for 12 years

55
Total CVEs
More Total CVEs than 98% of tracked products
4.6
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 29% of tracked products
1.8%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Asyncos over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 20, 2014
12 years ago
Most Recent CVE
Dec 17, 2025
219 days ago

CVE Severity & Scoring

Asyncos55 CVEs
All CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local5 (9.1%)
Network46 (83.6%)
Unknown4 (7.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low49 (89.1%)
High2 (3.6%)
Unknown4 (7.3%)
User Interaction
None43 (78.2%)
Unknown4 (7.3%)
Required8 (14.5%)
Privileges Required
Low14 (25.5%)
High8 (14.5%)
None29 (52.7%)
Unknown4 (7.3%)

Top CVEs

Signals from CVEs in this product scope (55 CVEs).

55 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could allow an unauthenticated, remot
Dec 17, 202510.086YESNO
A vulnerability in the web management interface of Cisco AsyncOS for Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow an aut
Nov 15, 20248.828NONO
A vulnerability in the configuration management of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to perform command injection a
Jul 8, 20218.828NONO
A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause t
Sep 23, 20208.628NONO
A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) could allow an unauthenticated, remote attacker to cause
Jan 10, 20198.628NONO
A vulnerability in the HTTPS decryption feature of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
Jul 4, 20198.627NONO
A vulnerability in the DNS-based Authentication of Named Entities (DANE) email verification component of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow
Feb 17, 20227.525NONO
Cisco AsyncOS 9.7.0-125 on Email Security Appliance (ESA) devices allows remote attackers to bypass intended spam filtering via crafted executable content in a ZIP archive, aka Bug
Jun 23, 20167.525NONO
A vulnerability in the email scanning algorithm of Cisco AsyncOS software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to perform a deni
Nov 4, 20217.524NONO
A vulnerability in the proxy service of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to exhaust system memory and cause a de
Oct 6, 20217.524NONO

Exploit Exposure

Signals from CVEs in this product scope (55 CVEs).

CISA KEV
1 CVE
1.8% of CVEs· 96th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (55 CVEs).

Media Mentions

Signals from CVEs in this product scope (55 CVEs).

Top CNAs Publishing CVEs For Asyncos

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.817.11.7%00
9.7.2-06517.80.4%00
9.7.0-12517.51.2%00
9.717.11.7%00
9.617.11.7%00
9.517.11.7%00
9.1.217.11.7%00
9.1.1-00517.80.4%00
9.117.11.7%00
9.0.0-08714.80.3%00
9.017.11.7%00
16.0.0-19514.80.3%00
16.0.0-05414.80.3%00
16.0.0-05014.80.3%00
15.5.3-02217.20.9%00
15.5.2-01836.20.4%00
15.5.2-00514.80.3%00
15.5.1-05546.00.4%00
15.5.1-02925.10.3%00
15.5.1-02425.10.3%00