Known vulnerabilities in Cisco Secure Email and Web Manager
Vendor:
Cisco Systems, Inc
Software:
Cisco Secure Email and Web Manager
Software CPE:
cpe:2.3:a:cisco_systems:cisco_secure_email_and_web_manager:*:*:*:*:*:*:*:*
Website:
https://www.cisco.com
Total vulnerabilities:
8
Public exploits:
0
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
Vulnerabilities (8)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU120181 - Improper input validation CVE-2025-20393 |
CWE-20 | Critical | 15.0.2-007, 15.5.4-007, 16.0.4-010 | 17.12.2025 |
SB2025121749 |
||
| #VU103668 - Exposure of sensitive information to an unauthorized actor CVE-2025-20207 |
CWE-200 | Medium | 15.5.2-005, 16.0.0-195 | 06.02.2025 |
SB2025020619 |
||
| #VU72309 - Improper input validation CVE-2023-20009 |
CWE-20 | Low | 12.8.1-021, 13.8.1-108, 14.2.0-224, 14.2.1-020, 14.3.0-120 | 15.02.2023 |
SB2023021588 |
||
| #VU68970 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') CVE-2022-20772 |
CWE-113 | Medium | 14.2.0-217, 14.3.0-115 | 04.11.2022 |
SB2022110408 |
||
| #VU64449 - Exposure of sensitive information to an unauthorized actor CVE-2022-20664 |
CWE-200 | Medium | 13.6.2-090, 14.1.0-227 | 16.06.2022 |
SB2022061617 |
||
| #VU64421 - Improper Authentication CVE-2022-20798 |
CWE-287 | Critical | 13.0.0-277, 13.6.2-090, 13.8.1-090, 14.0.0-418, 14.1.0-250 | 15.06.2022 |
SB2022061590 |
||
| #VU61942 - Uncaught Exception CVE-2022-20675 |
CWE-248 | Medium | 14.1.0-239 | 06.04.2022 |
SB2022040627 |
||
| #VU56026 - Improper Authentication CVE-2021-1561 |
CWE-287 | Medium | 14.1 | 23.08.2021 |
SB2021082301 |