CVE-2025-20393 Details
Description
A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to execute arbitrary system commands on an affected device with root privileges. This vulnerability is due to insufficient validation of HTTP requests by the Spam Quarantine feature. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with root privileges.
A vulnerability in Cisco Secure Email Gateway and Cisco Secure Email and Web Manager appliances, both physical and virtual, has been identified. This vulnerability allows threat actors to execute arbitrary commands with root privileges on the underlying operating system of affected appliances. The issue arises from improper input validation and affects all releases of Cisco AsyncOS Software. The vulnerability is exploitable when the Spam Quarantine feature is enabled and exposed to the internet.
Cisco recommends upgrading to the latest version of Cisco AsyncOS Software. For Cisco Secure Email Gateway, separate mail and management functionality onto different network interfaces to reduce the risk of unauthorized access. For Cisco Secure Email and Web Manager, ensure that the Spam Quarantine feature is not exposed to the internet. If an appliance has been compromised, rebuilding it is currently the only way to remove the threat actor's persistence mechanism.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 18, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-20393 | CISA-ADP | US Government Resource |
| https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sma-attack-N9bf4 | [email protected] | Vendor Advisory |
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| Cisco Multiple Products Improper Input Validation Vulnerability | Dec 17, 2025 | Dec 24, 2025 | Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cisco asyncos | < 15.0.5-016 >= 15.5, < 15.5.4-012 >= 16.0, < 16.0.4-016 < 15.0.2-007 >= 15.5, < 15.5.4-007 >= 16.0, < 16.0.4-010 |
CPE
Remediation
| |
| cisco secure email gateway virtual appliance c100v | All versions |
CPE
Remediation
| |
| cisco secure email gateway virtual appliance c300v | All versions |
CPE
Remediation
| |
| cisco secure email gateway virtual appliance c600v | All versions |
CPE
Remediation
| |
| cisco secure email gateway c195 | All versions |
CPE
Remediation
| |
| cisco secure email gateway c395 | All versions |
CPE
Remediation
| |
| cisco secure email gateway c695 | All versions |
CPE
Remediation
| |
| cisco secure email and web manager virtual appliance m100v | All versions |
CPE
Remediation
| |
| cisco secure email and web manager virtual appliance m300v | All versions |
CPE
Remediation
| |
| cisco secure email and web manager virtual appliance m600v | All versions |
CPE
Remediation
| |
| cisco secure email and web manager m170 | All versions |
CPE
Remediation
| |
| cisco secure email and web manager m190 | All versions |
CPE
Remediation
| |
| cisco secure email and web manager m195 | All versions |
CPE
Remediation
| |
| cisco secure email and web manager m380 | All versions |
CPE
Remediation
| |
| cisco secure email and web manager m390 | All versions |
CPE
Remediation
| |
| cisco secure email and web manager m390x | All versions |
CPE
Remediation
| |
| cisco secure email and web manager m395 | All versions |
CPE
Remediation
| |
| cisco secure email and web manager m680 | All versions |
CPE
Remediation
| |
| cisco secure email and web manager m690 | All versions |
CPE
Remediation
| |
| cisco secure email and web manager m690x | All versions |
CPE
Remediation
| |
| cisco secure email and web manager m695 | All versions |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jan 16, 2026 | Modified Analysis | [email protected] |
| Jan 15, 2026 | CVE Modified | [email protected] |
| Dec 18, 2025 | Initial Analysis | [email protected] |
| Dec 17, 2025 | CVE Modified | CISA-ADP |
| Dec 17, 2025 | New CVE Received | [email protected] |