


Perceptive Security
SOC/SIEM Consultancy

Cisco Secure Email Gateway, Secure Email, AsyncOS Software, and Web Manager appliances contains an improper input validation vulnerability that allows threat ac…
Published:
17 december 2025 om 00:00:00
Alert date:
17 december 2025 om 21:02:12
Source:
cisa.gov
A critical improper input validation vulnerability (CVE-2025-20393) affects multiple Cisco products including Secure Email Gateway, Secure Email, AsyncOS Software, and Web Manager appliances. The vulnerability allows threat actors to execute arbitrary commands with root privileges on the underlying operating system of affected appliances. This represents a high-severity security risk requiring immediate attention and mitigation according to Cisco's guidelines.
Technical details
Mitigation steps:
Affected products:
Cisco Secure Email Gateway
Cisco Secure Email
Cisco AsyncOS Software
Cisco Web Manager
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2025-20393
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sma-attack-N9bf4
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
