CVE-2025-20180

CVSS 3.1 Score 4.8 of 10 (medium)

Details

Published Feb 5, 2025
CWE ID 79

Summary

CVE-2025-20180 is a stored cross-site scripting (XSS) vulnerability affecting the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Email Gateway. The issue stems from insufficient user input validation, enabling authenticated, remote attackers to inject and execute arbitrary script code in users' web browsers. Successful exploitation could result in the attacker gaining access to sensitive information or taking control of the affected interface. To exploit this vulnerability, an attacker must possess valid credentials for a user account with a minimum role of Operator.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share