#VU103666 Input validation error in Cisco AsyncOS for Secure Web Appliance - CVE-2025-20183
Published: February 6, 2025
Cisco AsyncOS for Secure Web Appliance
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to improper handling of a crafted range request header in a policy-based Cisco Application Visibility and Control (AVC) implementation. A remote attacker can send a specially crafted HTTP request to evade the antivirus scanner and download a malicious file onto the endpoint.