CVE-2025-20393
A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to exe...
Affects 21 products across 1 vendor.
Software does not validate or incorrectly validates input, allowing attackers to craft data processed in unintended ways.
Show all 51
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
A critical vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager allows unauthenticated remote attackers to execute arbitrary commands with root privileges. This could lead to full system compromise and data exfiltration. Immediate action is required to mitigate the risk.
BSID: BS-2025-GLOBAL-270009-C • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2025-20393?
What is the CVSS score for CVE-2025-20393?
Is CVE-2025-20393 actively exploited?
How do I remediate CVE-2025-20393?
What systems are affected by CVE-2025-20393?
What NERC-CIP standard applies to CVE-2025-20393?
What IEC 62443 requirement maps to CVE-2025-20393?
| CVE ID | CVE-2025-20393 |
|---|---|
| BSID | BS-2025-GLOBAL-270009-C BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| Published | 2025-12-17 |
| Last Modified | 2026-01-16 |
| ICS Relevance | 75% |
| Weakness (CWE) | |
| Domains | |
| Source | NVD |
A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to execute arbitrary system commands on an affected device with root privileges. This vulnerability is due to insufficient validation of HTTP requests by the Spam Quarantine feature. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with root privileges.
Source: NIST NVD / MITRE CVE Database
The vulnerability is due to insufficient validation of HTTP requests by the Spam Quarantine feature. An attacker can exploit this by sending a crafted HTTP request to the affected device, leading to arbitrary command execution with root privileges.
Exploitation Likelihood: CRITICAL
| Vendor | Product | Fixed Version |
|---|---|---|
| Cisco | Asyncos | — |
| Cisco | Secure Email And Web Manager Virtual Appliance M100V | — |
| Cisco | Secure Email And Web Manager Virtual Appliance M300V | — |
| Cisco | Secure Email And Web Manager Virtual Appliance M600V | — |
| Cisco | Secure Email And Web Manager M170 | — |
| Cisco | Secure Email And Web Manager M190 | — |
| Cisco | Secure Email And Web Manager M195 | — |
| Cisco | Secure Email And Web Manager M380 | — |
| Cisco | Secure Email And Web Manager M390 | — |
| Cisco | Secure Email And Web Manager M390X | — |
| Cisco | Secure Email And Web Manager M395 | — |
| Cisco | Secure Email And Web Manager M680 | — |
| Cisco | Secure Email And Web Manager M690 | — |
| Cisco | Secure Email And Web Manager M690X | — |
| Cisco | Secure Email And Web Manager M695 | — |
| Cisco | Secure Email Gateway Virtual Appliance C100V | — |
| Cisco | Secure Email Gateway Virtual Appliance C300V | — |
| Cisco | Secure Email Gateway Virtual Appliance C600V | — |
| Cisco | Secure Email Gateway C195 | — |
| Cisco | Secure Email Gateway C395 | — |
| Cisco | Secure Email Gateway C695 | — |
No patch URL on record. Monitor vendor security advisories directly.
| CISA KEV | ● Active Exploitation Confirmed (added 2025-12-17) |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
Implement strict input validation and sanitization for all HTTP requests to the Spam Quarantine feature. Consider deploying a web application firewall (WAF) to filter out malicious requests.
No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. SAGE only publishes a network rule when a concrete on-the-wire signature can be grounded in the advisory.
This CVE violates CIP-007-R2 as it allows unauthorized access to the system, which could compromise the security of the electronic security perimeter.
This CVE maps to SR 7.6 as it involves a vulnerability in the software that could allow an attacker to gain unauthorized access and control over the system, leading to potential safety and operational disruptions.
Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.
SAGE Enrichment Record — provenance & audit hash
| Model | Qwen/Qwen2.5-72B-Instruct-AWQ |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | 5be074248647fc6d60ed377f8f8c6e720a3ffa88117f4d0815d6de5e20e0d8018a3b4e31d60bef76124fd778c2fd5847dd6bc19576f9774d8cb637759225ccc6 |
This Vulnerability Is Being Actively Exploited
CVE-2025-20393 is on the CISA KEV list - confirmed active exploitation in the wild. BreachSpider alerts your team within 15 minutes when KEV vulnerabilities match your ICS assets.
Start Free KEV Monitoring →