#VU103670 Execution with unnecessary privileges in Cisco Systems, Inc products - CVE-2025-20185
Published: February 6, 2025
Cisco AsyncOS for Secure Email Gateway
Cisco AsyncOS for Secure Web Appliance
Cisco AsyncOS for Secure Email and Web Manager
Cisco Systems, Inc
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to an architectural flaw in the password generation algorithm for the remote access functionality. A local user can generate a temporary password for the service account and execute arbitrary code on the system with root privileges.