Skip to main content
CISA Known Exploited Vulnerabilities

Cisco Multiple Products Improper Input Validation Vulnerability is confirmed as actively exploited and is listed in the CISA KEV catalog.

Added to KEV
2025-12-17
Remediation due
2025-12-24

Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CISA notes
Please adhere to Cisco's guidelines to assess exposure and mitigate risks. Check for signs of potential compromise on all internet accessible Cisco products affected by this vulnerability. Apply any final mitigations provided by the vendor as soon as they become available. For more information please see: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sma-attack-N9bf4 ; https://nvd.nist.gov/vuln/detail/CVE-2025-20393

Description

A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to execute arbitrary system commands on an affected device with root privileges. This vulnerability is due to insufficient validation of HTTP requests by the Spam Quarantine feature. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with root privileges.

Severity

CVSS 3.1 · CNA10 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SSVC · CISA-ADP
Exploitationactive
Automatableyes
Technical impacttotal

Affected Products

VendorProductAffected versions
CiscoCisco Secure Email
14.0.0-698
13.5.1-277
13.0.0-392
14.2.0-620
13.0.5-007
13.5.4-038
14.2.1-020
14.3.0-032
15.0.0-104
15.0.1-030
15.5.0-048
15.5.1-055
15.5.2-018
16.0.0-050
15.0.3-002
16.0.0-054
15.5.3-022
16.0.1-017
CiscoCisco Secure Email and Web Manager
13.6.2-023
13.6.2-078
13.0.0-249
13.0.0-277
13.8.1-052
13.8.1-068
13.8.1-074
14.0.0-404
12.8.1-002
14.1.0-227
13.6.1-201
14.2.0-203
14.2.0-212
12.8.1-021
13.8.1-108
14.2.0-224
14.3.0-120
15.0.0-334
15.5.1-024
15.5.1-029
15.5.2-005
16.0.0-195
15.5.3-017
16.0.1-010
15.0.1-035
16.0.2-088

References

1 Links

Record Details

Published
2025-12-17
Last updated
2026-02-26
Assigner (CNA)
cisco
Credited to
-

CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Exploited-in-the-wild data from the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not endorsed or certified by MITRE, NVD, CISA, or FIRST.