Information disclosure in Cisco Systems, Inc products - CVE-2025-20207
Published: February 6, 2025
Vulnerability identifier: #VU103668
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-20207
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application in Simple Network Management Protocol (SNMP) polling. A remote user can gain unauthorized access to sensitive information on the system.
Affected software
Cisco Secure Email and Web Manager
Secure Email Gateway
Secure Web Appliance
Secure Email Gateway
Secure Web Appliance
How to mitigate CVE-2025-20207
Install updates from vendor's website.
Cisco Secure Email and Web Manager - addressed in versions 15.5.2-005, 16.0.0-195
Secure Email Gateway - addressed in versions 15.0.3-002, 15.5.2-018, 16.0.0-050
Secure Web Appliance - addressed in versions 15.0.1-004, 15.2.1-010
Secure Email Gateway - addressed in versions 15.0.3-002, 15.5.2-018, 16.0.0-050
Secure Web Appliance - addressed in versions 15.0.1-004, 15.2.1-010