4.8
CVSSv3

CVE-2025-20180

CVSSv4: NA | CVSSv3: 4.8 | CVSSv2: NA | VMScore: 580 | EPSS: 0.00061 | KEV: Not Included
Published: 05/02/2025 Updated: 05/02/2025

Vulnerability Summary

Stored XSS Vulnerability in Cisco AsyncOS Software Management Interface

A vulnerability exists in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Email Gateway. This stored cross-site scripting (XSS) vulnerability could allow an authenticated, remote attacker to conduct an attack against interface users. The issue stems from insufficient validation of user input. An attacker with valid credentials at the Operator level or higher could persuade a user to click a crafted link. If successful, the attack could enable arbitrary script code execution within the interface context or allow access to sensitive browser-based information.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco cisco secure email

cisco cisco secure email and web manager