Asyncos
Vendor:
First CVE: May 20, 2014 · Active for 12 years
55
Total CVEs
More Total CVEs than 98% of tracked products
4.6
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 29% of tracked products
1.8%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Asyncos over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 20, 2014
12 years ago
Most Recent CVE
Dec 17, 2025
219 days ago
CVE Severity & Scoring
Asyncos55 CVEs
62%
36%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local5 (9.1%)
Network46 (83.6%)
Unknown4 (7.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low49 (89.1%)
High2 (3.6%)
Unknown4 (7.3%)
User Interaction
None43 (78.2%)
Unknown4 (7.3%)
Required8 (14.5%)
Privileges Required
Low14 (25.5%)
High8 (14.5%)
None29 (52.7%)
Unknown4 (7.3%)
Top CVEs
Signals from CVEs in this product scope (55 CVEs).
55 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-20393CRITICAL A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could allow an unauthenticated, remot | Dec 17, 2025 | 10.0 | 86 | YES | NO |
CVE-2022-20871HIGH A vulnerability in the web management interface of Cisco AsyncOS for Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow an aut | Nov 15, 2024 | 8.8 | 28 | NO | NO |
CVE-2021-1359HIGH A vulnerability in the configuration management of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to perform command injection a | Jul 8, 2021 | 8.8 | 28 | NO | NO |
CVE-2019-1947HIGH A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause t | Sep 23, 2020 | 8.6 | 28 | NO | NO |
CVE-2018-15460HIGH A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) could allow an unauthenticated, remote attacker to cause | Jan 10, 2019 | 8.6 | 28 | NO | NO |
CVE-2019-1886HIGH A vulnerability in the HTTPS decryption feature of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. | Jul 4, 2019 | 8.6 | 27 | NO | NO |
CVE-2022-20653HIGH A vulnerability in the DNS-based Authentication of Named Entities (DANE) email verification component of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow | Feb 17, 2022 | 7.5 | 25 | NO | NO |
CVE-2016-1438HIGH Cisco AsyncOS 9.7.0-125 on Email Security Appliance (ESA) devices allows remote attackers to bypass intended spam filtering via crafted executable content in a ZIP archive, aka Bug | Jun 23, 2016 | 7.5 | 25 | NO | NO |
CVE-2021-34741HIGH A vulnerability in the email scanning algorithm of Cisco AsyncOS software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to perform a deni | Nov 4, 2021 | 7.5 | 24 | NO | NO |
CVE-2021-34698HIGH A vulnerability in the proxy service of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to exhaust system memory and cause a de | Oct 6, 2021 | 7.5 | 24 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (55 CVEs).
CISA KEV
1 CVE
1.8% of CVEs· 96th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (55 CVEs).
Media Mentions
Signals from CVEs in this product scope (55 CVEs).
Top CNAs Publishing CVEs For Asyncos
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.8 | 1 | 7.1 | 1.7% | 0 | 0 |
| 9.7.2-065 | 1 | 7.8 | 0.4% | 0 | 0 |
| 9.7.0-125 | 1 | 7.5 | 1.2% | 0 | 0 |
| 9.7 | 1 | 7.1 | 1.7% | 0 | 0 |
| 9.6 | 1 | 7.1 | 1.7% | 0 | 0 |
| 9.5 | 1 | 7.1 | 1.7% | 0 | 0 |
| 9.1.2 | 1 | 7.1 | 1.7% | 0 | 0 |
| 9.1.1-005 | 1 | 7.8 | 0.4% | 0 | 0 |
| 9.1 | 1 | 7.1 | 1.7% | 0 | 0 |
| 9.0.0-087 | 1 | 4.8 | 0.3% | 0 | 0 |
| 9.0 | 1 | 7.1 | 1.7% | 0 | 0 |
| 16.0.0-195 | 1 | 4.8 | 0.3% | 0 | 0 |
| 16.0.0-054 | 1 | 4.8 | 0.3% | 0 | 0 |
| 16.0.0-050 | 1 | 4.8 | 0.3% | 0 | 0 |
| 15.5.3-022 | 1 | 7.2 | 0.9% | 0 | 0 |
| 15.5.2-018 | 3 | 6.2 | 0.4% | 0 | 0 |
| 15.5.2-005 | 1 | 4.8 | 0.3% | 0 | 0 |
| 15.5.1-055 | 4 | 6.0 | 0.4% | 0 | 0 |
| 15.5.1-029 | 2 | 5.1 | 0.3% | 0 | 0 |
| 15.5.1-024 | 2 | 5.1 | 0.3% | 0 | 0 |