Improper access control in Cisco AsyncOS for Secure Email Gateway - CVE-2025-20153

 

Improper access control in Cisco AsyncOS for Secure Email Gateway - CVE-2025-20153

Published: February 19, 2025


Vulnerability identifier: #VU104093
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-20153
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass configured filter rules.

The vulnerability exists due to improper access restrictions. A remote attacker can bypass the configured rules and allow emails that should have been denied to flow through an affected device.


Affected software

Cisco AsyncOS for Secure Email Gateway

How to mitigate CVE-2025-20153

Install updates from vendor's website.

Cisco AsyncOS for Secure Email Gateway - update to 16-0-0-054

External References

Related Security Bulletins