Improper access control in Cisco AsyncOS for Secure Email Gateway - CVE-2025-20153
Published: February 19, 2025
Vulnerability identifier: #VU104093
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-20153
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass configured filter rules.
The vulnerability exists due to improper access restrictions. A remote attacker can bypass the configured rules and allow emails that should have been denied to flow through an affected device.
Affected software
Cisco AsyncOS for Secure Email Gateway
How to mitigate CVE-2025-20153
Install updates from vendor's website.
Cisco AsyncOS for Secure Email Gateway - update to 16-0-0-054