CVE-2025-20393

9.5 CISA KEV

Cisco · AsyncOS Software (Secure Email Gateway and Secure Email and Web Manager)

A critical improper input validation vulnerability in the Spam Quarantine feature of Cisco AsyncOS allows unauthenticated remote attackers to execute arbitrary commands with root privileges.

Executive summary

Cisco Secure Email Gateway and Web Manager appliances are subject to active exploitation of a remote code execution vulnerability that grants attackers full root-level control over the device.

Vulnerability

This vulnerability stems from insufficient validation of HTTP requests within the Spam Quarantine feature. An unauthenticated remote attacker can exploit this flaw by sending a crafted HTTP request to the device, resulting in arbitrary command execution on the underlying operating system with root privileges.

Business impact

The exploitation of this vulnerability leads to a total compromise of the affected appliance, as the attacker gains root-level access. Given the critical CVSS score of 9.5, this represents a severe risk to organizational security, enabling threat actors to intercept sensitive email traffic, plant persistence mechanisms, or move laterally into the internal network. The inclusion of this vulnerability in the CISA Known Exploited Vulnerabilities catalog confirms that the risk is not theoretical and poses an immediate threat to operational integrity.

Remediation

Immediate Action: Upgrade to the patched versions provided by Cisco, which include 14.2.0-203, 14.2.0-212, 14.2.0-217, 14.2.0-224, 14.2.0-241, 15.0.0-334, 15.0.0-413, 15.0.0-418, 15.0.1-035, 15.5.1-029, 15.5.2-005, 15.5.3-017, 16.0.0-195, 16.0.1-010, 16.0.2-088, and 16.0.3-016.

Proactive Monitoring: Review system logs for anomalous HTTP requests targeting the Spam Quarantine interface and monitor for unexpected outbound connections or the presence of unauthorized files on the appliance filesystem.

Compensating Controls: If immediate patching is not possible, disable the Spam Quarantine feature or restrict access to the management interface to trusted internal networks only via firewall rules to prevent internet-based exploitation.

Exploitation status

Public Exploit Available: Yes, multiple public Proof-of-Concept repositories are available on GitHub.

Analyst recommendation

CVE-2025-20393 represents a critical risk to network security, and its status in the CISA KEV catalog mandates an immediate response. Administrators must prioritize the application of the vendor-provided security updates to ensure the vulnerability is fully remediated. If patching cannot be performed immediately, network-level access restrictions must be implemented to isolate the affected Spam Quarantine feature from untrusted networks.

More Cisco CVEs

Sources