CVE-2025-20183
CVSS 3.1 Score 5.8 of 10 (medium)
Details
Summary
CVE-2025-20183 is a vulnerability affecting the policy-based implementation of Cisco Application Visibility and Control (AVC) in Cisco AsyncOS Software for Cisco Secure Web Appliance. An unauthenticated, remote attacker can exploit this issue by sending a crafted range request header in an HTTP request. The vulnerability arises from improper handling of such requests, enabling the attacker to bypass the antivirus scanner and download malicious files onto the endpoint undetected by Cisco Secure Web Appliance. Successful exploitation could lead to potential security risks and data compromise. Users are advised to update their software to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.