Security
Loading…

CVE-2025-20393

UNKNOWNKnown Exploited
Description

Cisco Secure Email Gateway, Secure Email, AsyncOS Software, and Web Manager appliances contains an improper input validation vulnerability that allows threat actors to execute arbitrary commands with root privileges on the underlying operating system of an affected appliance.

Timeline
Published:December 17th, 2025 12:00 AM
Last modified:December 17th, 2025 12:00 AM
Added to KEV:December 17th, 2025
CVSS Scoring

No CVSS v3 score available

Affected Software
From NVD CPE configuration data

Vendors

Cisco

Products

Multiple Products
Weaknesses (CWE)
References & Reports
Advisories, patches, and third-party reports

No references available.

Source: CISA KEV + NVD · Data may lag official sources by up to one minute