Execution with unnecessary privileges in Cisco Systems, Inc products - CVE-2025-20185
Published: February 6, 2025
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to an architectural flaw in the password generation algorithm for the remote access functionality. A local user can generate a temporary password for the service account and execute arbitrary code on the system with root privileges.
Affected software
Cisco AsyncOS for Secure Email and Web Manager
Cisco AsyncOS for Secure Web Appliance
How to mitigate CVE-2025-20185
Cisco AsyncOS for Secure Web Appliance - update to 15.2.2-009
Cisco AsyncOS for Secure Email and Web Manager - addressed in versions 15.5.3-017, 16.0.1-010