LIVE NEWSROOM · --:-- · May 25, 2026
A LIBRARY FOR SECURITY RESEARCHERS

CVE DATABASE  /  CVE-2025-20393

CVE-2025-20393

Cisco Multiple Products Improper Input Validation Vulnerability

CVSS 10 · CRITICAL ⚠ CISA KEV — ACTIVELY EXPLOITED
On the CISA KEV catalog

Confirmed exploited in the wild. Added 2025-12-17. Federal remediation due 2025-12-24.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Summary

A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to execute arbitrary system commands on an affected device with root privileges.This vulnerability is due to insufficient validation of HTTP requests by the Spam Quarantine feature. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with root privileges.

CVSS 3.1 breakdown

Base score10 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack vectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeCHANGED
ConfidentialityHIGH
IntegrityHIGH
AvailabilityHIGH

Weakness type (CWE)

Affected products

Cisco asyncosCisco secure email gateway virtual appliance c100vCisco secure email gateway virtual appliance c300vCisco secure email gateway virtual appliance c600vCisco secure email gateway c195Cisco secure email gateway c395Cisco secure email gateway c695Cisco secure email and web manager virtual appliance m100vCisco secure email and web manager virtual appliance m300vCisco secure email and web manager virtual appliance m600vCisco secure email and web manager m170Cisco secure email and web manager m190Cisco secure email and web manager m195Cisco secure email and web manager m380Cisco secure email and web manager m390Cisco secure email and web manager m390xCisco secure email and web manager m395Cisco secure email and web manager m680Cisco secure email and web manager m690Cisco secure email and web manager m690x
Check this CVE live

Use our free CVE Lookup tool for the latest NVD record, or browse the full CISA KEV catalog.

References

Data: NIST NVD + CISA KEV. NVD last modified 2026-01-16. Always verify against the vendor advisory before acting.

Scroll to Top