top of page
perceptive_background_267k.jpg

Cisco Secure Email Gateway, Secure Email, AsyncOS Software, and Web Manager appliances contains an improper input validation vulnerability that allows threat ac…

Published:

17 December 2025 at 00:00:00

Alert date:

17 December 2025 at 21:02:12

Source:

cisa.gov

Click to open the original link from this advisory

A critical improper input validation vulnerability (CVE-2025-20393) affects multiple Cisco products including Secure Email Gateway, Secure Email, AsyncOS Software, and Web Manager appliances. The vulnerability allows threat actors to execute arbitrary commands with root privileges on the underlying operating system of affected appliances. This represents a high-severity security risk requiring immediate attention and mitigation according to Cisco's guidelines.

Technical details

Mitigation steps:

Affected products:

Cisco Secure Email Gateway
Cisco Secure Email
Cisco AsyncOS Software
Cisco Web Manager

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page