VendorsCiscoasyncos15.5.0-048
Vulnerabilities

Cisco AsyncOS 15.5.0-048

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2025-20184
Cisco Secure Email and Web Manager and Secure Web Appliance Command Injection Vulnerability
Published 2025-02-05 · Analyzed
7.2EPSS 0.009
CVE-2025-20185
Cisco Secure Email and Web Manager, Secure Email Gateway, and Secure Web Appliance Privilege Escalation Vulnerability
Published 2025-02-05 · Analyzed
6.7EPSS 0.002
CVE-2024-20392
A vulnerability in the web-based management API of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack. This vulnerability is due to insufficient input validation of some parameters that are passed to the web-based management API of the affected system. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to perform cross-site scripting (XSS) attacks, resulting in the execution of arbitrary script code in the browser of the targeted user, or could allow the attacker to access sensitive, browser-based information.
Published 2024-05-15 · Analyzed
6.1EPSS 0.004
CVE-2024-20504
Cisco Secure Email and Web Manager, Secure Email Gateway, and Secure Web Appliance Stored Cross-Site Scripting Vulnerabilities
Published 2024-11-06 · Analyzed
5.4EPSS 0.003
CVE-2025-20180
Cisco Secure Email and Web Manager and Secure Email Gateway Cross-Site Scripting Vulnerability
Published 2025-02-05 · Analyzed
4.8EPSS 0.003
CVE-2024-20257
A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface.r This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
Published 2024-05-15 · Analyzed
4.8EPSS 0.003