Execution with unnecessary privileges in Cisco Systems, Inc products - CVE-2025-20185

 

Execution with unnecessary privileges in Cisco Systems, Inc products - CVE-2025-20185

Published: February 6, 2025


Vulnerability identifier: #VU103670
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-20185
CWE-ID: CWE-250
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to an architectural flaw in the password generation algorithm for the remote access functionality. A local user can generate a temporary password for the service account and execute arbitrary code on the system with root privileges.


Affected software

Cisco AsyncOS for Secure Email Gateway
Cisco AsyncOS for Secure Email and Web Manager
Cisco AsyncOS for Secure Web Appliance

How to mitigate CVE-2025-20185

Install updates from vendor's website.

Cisco AsyncOS for Secure Email Gateway - addressed in versions 15.5.3-022, 16.0.1-017
Cisco AsyncOS for Secure Web Appliance - update to 15.2.2-009
Cisco AsyncOS for Secure Email and Web Manager - addressed in versions 15.5.3-017, 16.0.1-010

External References

Related Security Bulletins