CVE-2025-20393

● KEV CRITICAL

A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to exe...

Affects 21 products across 1 vendor.

BCS9.82
CVSS 3.110.0
EPSS29.5%
Percentile98th
PatchUnknown
KEV Added2025-12-17
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, can impact systems beyond the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-20: Improper Input Validation

Software does not validate or incorrectly validates input, allowing attackers to craft data processed in unintended ways.

Related Attack Patterns (CAPEC)
CAPEC-3 Using Leading 'Ghost' Character Sequences to Bypass Input Filters
via CWE-20
CAPEC-7 Blind SQL Injection
via CWE-20
CAPEC-8 Buffer Overflow in an API Call
via CWE-20
CAPEC-9 Buffer Overflow in Local Command-Line Utilities
via CWE-20
CAPEC-10 Buffer Overflow via Environment Variables
via CWE-20
Show all 51
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A critical vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager allows unauthenticated remote attackers to execute arbitrary commands with root privileges. This could lead to full system compromise and data exfiltration. Immediate action is required to mitigate the risk.

BSID: BS-2025-GLOBAL-270009-C • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2025-20393?
A critical vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager allows unauthenticated remote attackers to execute arbitrary commands with root privileges. This could lead to full system compromise and data exfiltration. Immediate action is required to mitigate the risk.
What is the CVSS score for CVE-2025-20393?
CVE-2025-20393 has CVSS 10.0 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. EPSS: 29.5%.
Is CVE-2025-20393 actively exploited?
Yes. CVE-2025-20393 is in the CISA KEV catalog (added 2025-12-17). Active exploitation confirmed. Immediate patching required.
How do I remediate CVE-2025-20393?
Priority: IMMEDIATE.
What systems are affected by CVE-2025-20393?
CVE-2025-20393 affects: Cisco, Cisco, Cisco, Cisco, Cisco, Cisco, Cisco, Cisco.
What NERC-CIP standard applies to CVE-2025-20393?
NERC CIP CIP-007 CIP-007-R2: This CVE violates CIP-007-R2 as it allows unauthorized access to the system, which could compromise the security of the electronic security perimeter.
What IEC 62443 requirement maps to CVE-2025-20393?
IEC 62443 SR 7.6: This CVE maps to SR 7.6 as it involves a vulnerability in the software that could allow an attacker to gain unauthorized access and control over the system, leading to potential safety and operational disruptions.
Vulnerability Details
CVE IDCVE-2025-20393
BSIDBS-2025-GLOBAL-270009-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Published2025-12-17
Last Modified2026-01-16
ICS Relevance75%
Weakness (CWE)
Domains
NETWORK-INFRA
SourceNVD
Official Description

A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to execute arbitrary system commands on an affected device with root privileges. This vulnerability is due to insufficient validation of HTTP requests by the Spam Quarantine feature. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with root privileges.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability is due to insufficient validation of HTTP requests by the Spam Quarantine feature. An attacker can exploit this by sending a crafted HTTP request to the affected device, leading to arbitrary command execution with root privileges.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Cisco Asyncos
Cisco Secure Email And Web Manager Virtual Appliance M100V
Cisco Secure Email And Web Manager Virtual Appliance M300V
Cisco Secure Email And Web Manager Virtual Appliance M600V
Cisco Secure Email And Web Manager M170
Cisco Secure Email And Web Manager M190
Cisco Secure Email And Web Manager M195
Cisco Secure Email And Web Manager M380
Cisco Secure Email And Web Manager M390
Cisco Secure Email And Web Manager M390X
Cisco Secure Email And Web Manager M395
Cisco Secure Email And Web Manager M680
Cisco Secure Email And Web Manager M690
Cisco Secure Email And Web Manager M690X
Cisco Secure Email And Web Manager M695
Cisco Secure Email Gateway Virtual Appliance C100V
Cisco Secure Email Gateway Virtual Appliance C300V
Cisco Secure Email Gateway Virtual Appliance C600V
Cisco Secure Email Gateway C195
Cisco Secure Email Gateway C395
Cisco Secure Email Gateway C695
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 220 Days
CISA KEV● Active Exploitation Confirmed (added 2025-12-17)
Public ExploitNot confirmed
PoC CodeNot confirmed
● Virtual Patch — CITED Relevance SAGE Engine MEDIUM CONFIDENCE

Implement strict input validation and sanitization for all HTTP requests to the Spam Quarantine feature. Consider deploying a web application firewall (WAF) to filter out malicious requests.

No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. SAGE only publishes a network rule when a concrete on-the-wire signature can be grounded in the advisory.

NERC CIP: CIP-007 CIP-007-R2
This CVE violates CIP-007-R2 as it allows unauthorized access to the system, which could compromise the security of the electronic security perimeter.
IEC 62443: SR 7.6
This CVE maps to SR 7.6 as it involves a vulnerability in the software that could allow an attacker to gain unauthorized access and control over the system, leading to potential safety and operational disruptions.

Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.

SAGE Enrichment Record — provenance & audit hash
ModelQwen/Qwen2.5-72B-Instruct-AWQ
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash5be074248647fc6d60ed377f8f8c6e720a3ffa88117f4d0815d6de5e20e0d8018a3b4e31d60bef76124fd778c2fd5847dd6bc19576f9774d8cb637759225ccc6
Related CVEs affecting Cisco
CVE-2007-2036 10.0 The SNMP implementation in the Cisco Wireless LAN Controller (WLC) before 200... CVE-2003-0732 10.0 CiscoWorks Common Management Foundation (CMF) 2.1 and earlier allows the gues... CVE-2004-0308 10.0 Unknown vulnerability in Cisco ONS 15327 before 4.1(3), ONS 15454 before 4.6(... CVE-2007-5382 10.0 The conversion utility for converting CiscoWorks Wireless LAN Solution Engine... CVE-1999-0775 10.0 Cisco Gigabit Switch routers running IOS allow remote attackers to forward un...
View all Cisco CVEs →

This Vulnerability Is Being Actively Exploited

CVE-2025-20393 is on the CISA KEV list - confirmed active exploitation in the wild. BreachSpider alerts your team within 15 minutes when KEV vulnerabilities match your ICS assets.

Start Free KEV Monitoring →