CVE-2025-20153 Details
Description
A vulnerability in the email filtering mechanism of Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to bypass the configured rules and allow emails that should have been denied to flow through an affected device. This vulnerability is due to improper handling of email that passes through an affected device. An attacker could exploit this vulnerability by sending a crafted email through the affected device. A successful exploit could allow the attacker to bypass email filters on the affected device.
A vulnerability exists in the email filtering mechanism of Cisco Secure Email Gateway, allowing an unauthenticated, remote attacker to bypass established email rules. This flaw enables emails that should have been blocked to be delivered through affected devices. The issue arises from improper handling of certain emails, which attackers can exploit by sending crafted messages that evade filters.
Cisco has released software updates to address this vulnerability. Instructions for upgrading can be found in the Cisco Security Vulnerability Policy. Users should consult the Cisco Security Advisories page for information on fixed releases.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 19, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-mailpol-bypass-5nVcJZMw | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-284 | Improper Access Control | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cisco secure email gateway | 13.0.0-392 13.0.5-007 13.5.1-277 13.5.4-038 14.0.0-698 14.2.0-620 14.2.1-020 14.3.0-032 15.0.0-104 15.0.1-030 15.0.3-002 15.5.0-048 15.5.1-055 15.5.2-018 16.0.0-050 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 31, 2025 | Initial Analysis | [email protected] |
| Feb 19, 2025 | New CVE Received | [email protected] |