Stored XSS Vulnerability in Cisco AsyncOS Software for Email and Web Management
CVE-2025-20180

4.8MEDIUM

Key Information:

Vendor
Cisco
Vendor
CVE Published:
5 February 2025

Badges

👾 Exploit Exists

Summary

A stored cross-site scripting vulnerability exists in the web-based management interface of Cisco AsyncOS Software for the Cisco Secure Email and Web Manager and Secure Email Gateway. This vulnerability arises from inadequate validation of user input, allowing an authenticated remote attacker to craft a malicious link that, when clicked by a user, could execute arbitrary script code in the browser context of the affected interface. Successful exploitation enables the attacker to access sensitive information from the user's session. To launch this attack, the assailant must possess valid credentials for a user account with at least Operator privileges.

Affected Version(s)

Cisco Secure Email 14.0.0-698

Cisco Secure Email 13.5.1-277

Cisco Secure Email 13.0.0-392

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.