Email Filtering Bypass in Cisco Secure Email Gateway
CVE-2025-20153

5.8MEDIUM

Key Information:

Vendor
Cisco
Vendor
CVE Published:
19 February 2025

Badges

👾 Exploit Exists

Summary

A vulnerability exists in the email filtering mechanism of Cisco Secure Email Gateway, enabling an unauthenticated remote attacker to bypass established email rules. This issue arises from improper processing of emails that transit through the device. An attacker could exploit this flaw by sending a specially crafted email, allowing unauthorized messages that should be blocked to pass through the system. This situation poses significant risks to email security and could lead to further exploitation.

Affected Version(s)

Cisco Secure Email 14.0.0-698

Cisco Secure Email 13.5.1-277

Cisco Secure Email 13.0.0-392

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.