CVE Feed

    Dashboard / CVE / CVE-2025-20393

    CVE-2025-20393

    A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to execute arbitrary system commands on an affected device with root privileges. This vulnerability is due to insufficient validation of HTTP requests by the Spam Quarantine feature. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with root privileges.

    Published:Dec 17, 2025
    Last Modified:Feb 26, 2026
    EPS:Dec 17, 2025
    EPSS Score:0.0496
    CVSS Score:10

    CISA Notification

    Description

    A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to execute arbitrary system commands on an affected device with root privileges. This vulnerability is due to insufficient validation of HTTP requests by the Spam Quarantine feature. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with root privileges.

    Required Action:

    Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

    Notes:

    No extra notes provided.

    Due Date
    Dec 24, 2025
    261 days ago
    Alert Date
    Dec 17, 2025
    268 days ago

    Affected Products

    Vendor
    Cisco
    Product
    Asyncos
    Vendor
    Cisco
    Product
    Secure Email
    Vendor
    Cisco
    Product
    Secure Email And Web Manager
    Vendor
    Cisco
    Product
    Secure Email And Web Manager M170
    Vendor
    Cisco
    Product
    Secure Email And Web Manager M190
    Vendor
    Cisco
    Product
    Secure Email And Web Manager M195
    Vendor
    Cisco
    Product
    Secure Email And Web Manager M380
    Vendor
    Cisco
    Product
    Secure Email And Web Manager M390
    Vendor
    Cisco
    Product
    Secure Email And Web Manager M390x
    Vendor
    Cisco
    Product
    Secure Email And Web Manager M395
    Vendor
    Cisco
    Product
    Secure Email And Web Manager M680
    Vendor
    Cisco
    Product
    Secure Email And Web Manager M690
    Vendor
    Cisco
    Product
    Secure Email And Web Manager M690x
    Vendor
    Cisco
    Product
    Secure Email And Web Manager M695
    Vendor
    Cisco
    Product
    Secure Email And Web Manager Virtual Appliance M100v
    Vendor
    Cisco
    Product
    Secure Email And Web Manager Virtual Appliance M300v
    Vendor
    Cisco
    Product
    Secure Email And Web Manager Virtual Appliance M600v
    Vendor
    Cisco
    Product
    Secure Email Gateway
    Vendor
    Cisco
    Product
    Secure Email Gateway C195
    Vendor
    Cisco
    Product
    Secure Email Gateway C395
    Vendor
    Cisco
    Product
    Secure Email Gateway C695
    Vendor
    Cisco
    Product
    Secure Email Gateway Virtual Appliance C100v
    Vendor
    Cisco
    Product
    Secure Email Gateway Virtual Appliance C300v
    Vendor
    Cisco
    Product
    Secure Email Gateway Virtual Appliance C600v

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High