CVE-2025-20184
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2025-20184 is a vulnerability affecting the web-based management interface of Cisco AsyncOS Software used by Cisco Secure Email Gateway and Cisco Secure Web Appliance. An authenticated, remote attacker can exploit this issue by uploading a maliciously crafted XML configuration file. The vulnerability stems from insufficient validation of these files, which could allow the attacker to inject commands into the underlying operating system with root privileges. Successful exploitation could lead to significant security risks, including unauthorized system access and control. Authentic administrator credentials are required for an attacker to exploit this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.