CVE-2025-20180
CVSS 3.1 Score 4.8 of 10 (medium)
Details
Summary
CVE-2025-20180 is a stored cross-site scripting (XSS) vulnerability affecting the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Email Gateway. The issue stems from insufficient user input validation, enabling authenticated, remote attackers to inject and execute arbitrary script code in users' web browsers. Successful exploitation could result in the attacker gaining access to sensitive information or taking control of the affected interface. To exploit this vulnerability, an attacker must possess valid credentials for a user account with a minimum role of Operator.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.