Search

Find a vulnerability

Search criteria

    56 vulnerabilities found for Cisco Secure Email by Cisco

    CVE-2026-76461 (GCVE-0-2026-76461)

    Vulnerability from nvd – Published: 2026-09-14 16:09 – Updated: 2026-09-18 12:10
    VLAI CISA Previdian
    Title
    Cisco Secure Email Gateway SQL Injection Vulnerability
    Summary
    A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.
    SSVC
    Exploitation: active Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-14 00:00 UTC
    CWE
    • CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
    Impacted products
    Vendor Product Version
    Cisco Cisco Secure Email Affected: 14.0.0-698
    Affected: 13.5.1-277
    Affected: 13.0.0-392
    Affected: 14.2.0-620
    Affected: 13.0.5-007
    Affected: 13.5.4-038
    Affected: 14.2.1-020
    Affected: 14.3.0-032
    Affected: 15.0.0-104
    Affected: 15.0.1-030
    Affected: 15.5.0-048
    Affected: 15.5.1-055
    Affected: 15.5.2-018
    Affected: 16.0.0-050
    Affected: 15.0.3-002
    Affected: 16.0.0-054
    Affected: 15.5.3-022
    Affected: 16.0.1-017
    Affected: 15.5.4-012
    Affected: 16.0.4-016
    Affected: 15.0.5-016
    Affected: 16.0.2-112
    Affected: 16.0.3-044
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-76461",
                    "options": [
                      {
                        "Exploitation": "active"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-14T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              },
              {
                "other": {
                  "content": {
                    "dateAdded": "2026-09-14",
                    "reference": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-76461"
                  },
                  "type": "kev"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-15T03:56:06.270Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "government-resource"
                ],
                "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-76461"
              }
            ],
            "timeline": [
              {
                "lang": "en",
                "time": "2026-09-14T00:00:00.000Z",
                "value": "CVE-2026-76461 added to CISA KEV"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "Cisco Secure Email",
              "vendor": "Cisco",
              "versions": [
                {
                  "status": "affected",
                  "version": "14.0.0-698"
                },
                {
                  "status": "affected",
                  "version": "13.5.1-277"
                },
                {
                  "status": "affected",
                  "version": "13.0.0-392"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-620"
                },
                {
                  "status": "affected",
                  "version": "13.0.5-007"
                },
                {
                  "status": "affected",
                  "version": "13.5.4-038"
                },
                {
                  "status": "affected",
                  "version": "14.2.1-020"
                },
                {
                  "status": "affected",
                  "version": "14.3.0-032"
                },
                {
                  "status": "affected",
                  "version": "15.0.0-104"
                },
                {
                  "status": "affected",
                  "version": "15.0.1-030"
                },
                {
                  "status": "affected",
                  "version": "15.5.0-048"
                },
                {
                  "status": "affected",
                  "version": "15.5.1-055"
                },
                {
                  "status": "affected",
                  "version": "15.5.2-018"
                },
                {
                  "status": "affected",
                  "version": "16.0.0-050"
                },
                {
                  "status": "affected",
                  "version": "15.0.3-002"
                },
                {
                  "status": "affected",
                  "version": "16.0.0-054"
                },
                {
                  "status": "affected",
                  "version": "15.5.3-022"
                },
                {
                  "status": "affected",
                  "version": "16.0.1-017"
                },
                {
                  "status": "affected",
                  "version": "15.5.4-012"
                },
                {
                  "status": "affected",
                  "version": "16.0.4-016"
                },
                {
                  "status": "affected",
                  "version": "15.0.5-016"
                },
                {
                  "status": "affected",
                  "version": "16.0.2-112"
                },
                {
                  "status": "affected",
                  "version": "16.0.3-044"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.\r\n\r\nThis vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system."
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "value": "In September 2026, the\u00a0Cisco PSIRT became aware of active exploitation of this vulnerability."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "cvssV3_1"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-89",
                  "description": "Improper Neutralization of Special Elements used in an SQL Command (\u0027SQL Injection\u0027)",
                  "lang": "en",
                  "type": "cwe"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-18T12:10:27.392Z",
            "orgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
            "shortName": "cisco"
          },
          "references": [
            {
              "name": "cisco-sa-esa-inj-2bLVGmhX",
              "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX"
            }
          ],
          "source": {
            "advisory": "cisco-sa-esa-inj-2bLVGmhX",
            "defects": [
              "CSCwu56234"
            ],
            "discovery": "INTERNAL"
          },
          "title": "Cisco Secure Email Gateway SQL Injection Vulnerability"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
        "assignerShortName": "cisco",
        "cveId": "CVE-2026-76461",
        "datePublished": "2026-09-14T16:09:07.839Z",
        "dateReserved": "2026-08-19T12:02:03.637Z",
        "dateUpdated": "2026-09-18T12:10:27.392Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-76443 (GCVE-0-2026-76443)

    Vulnerability from nvd – Published: 2026-09-14 16:08 – Updated: 2026-09-15 17:03
    VLAI
    Title
    Cisco Secure Email Gateway Security Hardening Release
    Summary
    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76443 are related to issues with improper neutralization that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-707.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-14 00:00 UTC
    CWE
    • CWE-707 - Improper Neutralization
    Impacted products
    Vendor Product Version
    Cisco Cisco Secure Email Affected: 14.0.0-698
    Affected: 13.5.1-277
    Affected: 13.0.0-392
    Affected: 14.2.0-620
    Affected: 13.0.5-007
    Affected: 13.5.4-038
    Affected: 14.2.1-020
    Affected: 14.3.0-032
    Affected: 15.0.0-104
    Affected: 15.0.1-030
    Affected: 15.5.0-048
    Affected: 15.5.1-055
    Affected: 15.5.2-018
    Affected: 16.0.0-050
    Affected: 15.0.3-002
    Affected: 16.0.0-054
    Affected: 15.5.3-022
    Affected: 16.0.1-017
    Affected: 15.5.4-012
    Affected: 16.0.4-016
    Affected: 15.0.5-016
    Affected: 16.0.2-112
    Affected: 16.0.3-044
    Create a notification for this product.
    Cisco Cisco Secure Email and Web Manager Affected: 13.6.2-023
    Affected: 13.6.2-078
    Affected: 13.0.0-249
    Affected: 13.0.0-277
    Affected: 13.8.1-052
    Affected: 13.8.1-068
    Affected: 13.8.1-074
    Affected: 14.0.0-404
    Affected: 12.8.1-002
    Affected: 14.1.0-227
    Affected: 13.6.1-201
    Affected: 14.2.0-203
    Affected: 14.2.0-212
    Affected: 12.8.1-021
    Affected: 13.8.1-108
    Affected: 14.2.0-224
    Affected: 14.3.0-120
    Affected: 15.0.0-334
    Affected: 15.5.1-024
    Affected: 15.5.1-029
    Affected: 15.5.2-005
    Affected: 16.0.0-195
    Affected: 15.5.3-017
    Affected: 16.0.1-010
    Affected: 15.0.1-035
    Affected: 16.0.2-088
    Affected: 15.5.4-007
    Affected: 15.0.2-007
    Affected: 16.0.4-010
    Affected: 16.0.3-016
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-76443",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-14T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-15T03:56:11.795Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "descriptions": [
              {
                "lang": "en",
                "value": "The CVE Program recognizes that this CVE Record provides vulnerability information that a Supplier CNA believes is very important to consumers. The CVE Program has flagged this CVE Record as it assigns a single CVE ID to a collection of individual vulnerabilities which does not align with CVE\u0027s \"one vulnerability, one ID\" principle, and therefore provides incomplete information. For further clarification, please see the CVE Program\u0027s blog, \"Preserving Vulnerability-Level Identification\" linked below. Details within the CNA container below are viewable by clicking on the CNA name."
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-15T17:03:58.065Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://www.cve.org/Media/News/item/blog/2026/06/16/Preserving-Vulnerability-Level-Identification"
              }
            ],
            "tags": [
              "x_bundling-flagged-by-CVE-Program"
            ]
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "Cisco Secure Email",
              "vendor": "Cisco",
              "versions": [
                {
                  "status": "affected",
                  "version": "14.0.0-698"
                },
                {
                  "status": "affected",
                  "version": "13.5.1-277"
                },
                {
                  "status": "affected",
                  "version": "13.0.0-392"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-620"
                },
                {
                  "status": "affected",
                  "version": "13.0.5-007"
                },
                {
                  "status": "affected",
                  "version": "13.5.4-038"
                },
                {
                  "status": "affected",
                  "version": "14.2.1-020"
                },
                {
                  "status": "affected",
                  "version": "14.3.0-032"
                },
                {
                  "status": "affected",
                  "version": "15.0.0-104"
                },
                {
                  "status": "affected",
                  "version": "15.0.1-030"
                },
                {
                  "status": "affected",
                  "version": "15.5.0-048"
                },
                {
                  "status": "affected",
                  "version": "15.5.1-055"
                },
                {
                  "status": "affected",
                  "version": "15.5.2-018"
                },
                {
                  "status": "affected",
                  "version": "16.0.0-050"
                },
                {
                  "status": "affected",
                  "version": "15.0.3-002"
                },
                {
                  "status": "affected",
                  "version": "16.0.0-054"
                },
                {
                  "status": "affected",
                  "version": "15.5.3-022"
                },
                {
                  "status": "affected",
                  "version": "16.0.1-017"
                },
                {
                  "status": "affected",
                  "version": "15.5.4-012"
                },
                {
                  "status": "affected",
                  "version": "16.0.4-016"
                },
                {
                  "status": "affected",
                  "version": "15.0.5-016"
                },
                {
                  "status": "affected",
                  "version": "16.0.2-112"
                },
                {
                  "status": "affected",
                  "version": "16.0.3-044"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "Cisco Secure Email and Web Manager",
              "vendor": "Cisco",
              "versions": [
                {
                  "status": "affected",
                  "version": "13.6.2-023"
                },
                {
                  "status": "affected",
                  "version": "13.6.2-078"
                },
                {
                  "status": "affected",
                  "version": "13.0.0-249"
                },
                {
                  "status": "affected",
                  "version": "13.0.0-277"
                },
                {
                  "status": "affected",
                  "version": "13.8.1-052"
                },
                {
                  "status": "affected",
                  "version": "13.8.1-068"
                },
                {
                  "status": "affected",
                  "version": "13.8.1-074"
                },
                {
                  "status": "affected",
                  "version": "14.0.0-404"
                },
                {
                  "status": "affected",
                  "version": "12.8.1-002"
                },
                {
                  "status": "affected",
                  "version": "14.1.0-227"
                },
                {
                  "status": "affected",
                  "version": "13.6.1-201"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-203"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-212"
                },
                {
                  "status": "affected",
                  "version": "12.8.1-021"
                },
                {
                  "status": "affected",
                  "version": "13.8.1-108"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-224"
                },
                {
                  "status": "affected",
                  "version": "14.3.0-120"
                },
                {
                  "status": "affected",
                  "version": "15.0.0-334"
                },
                {
                  "status": "affected",
                  "version": "15.5.1-024"
                },
                {
                  "status": "affected",
                  "version": "15.5.1-029"
                },
                {
                  "status": "affected",
                  "version": "15.5.2-005"
                },
                {
                  "status": "affected",
                  "version": "16.0.0-195"
                },
                {
                  "status": "affected",
                  "version": "15.5.3-017"
                },
                {
                  "status": "affected",
                  "version": "16.0.1-010"
                },
                {
                  "status": "affected",
                  "version": "15.0.1-035"
                },
                {
                  "status": "affected",
                  "version": "16.0.2-088"
                },
                {
                  "status": "affected",
                  "version": "15.5.4-007"
                },
                {
                  "status": "affected",
                  "version": "15.0.2-007"
                },
                {
                  "status": "affected",
                  "version": "16.0.4-010"
                },
                {
                  "status": "affected",
                  "version": "16.0.3-016"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "As part of Cisco\u0027s ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-76443 are related to issues with improper neutralization that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-707."
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "value": "Except as otherwise noted previously, the Cisco PSIRT is not aware of any public announcements or malicious use of the vulnerabilities that are described in this advisory."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "cvssV3_1"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-707",
                  "description": "Improper Neutralization",
                  "lang": "en",
                  "type": "cwe"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-14T16:08:59.278Z",
            "orgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
            "shortName": "cisco"
          },
          "references": [
            {
              "name": "cisco-sa-hardening-esa-dfCrfXkm",
              "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm"
            }
          ],
          "source": {
            "advisory": "cisco-sa-hardening-esa-dfCrfXkm",
            "defects": [
              "CSCwu56232"
            ],
            "discovery": "INTERNAL"
          },
          "title": "Cisco Secure Email Gateway Security Hardening Release"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
        "assignerShortName": "cisco",
        "cveId": "CVE-2026-76443",
        "datePublished": "2026-09-14T16:08:59.278Z",
        "dateReserved": "2026-08-19T12:02:03.635Z",
        "dateUpdated": "2026-09-15T17:03:58.065Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-76442 (GCVE-0-2026-76442)

    Vulnerability from nvd – Published: 2026-09-14 16:09 – Updated: 2026-09-16 03:55
    VLAI
    Title
    Cisco Secure Email Gateway Security Hardening Release
    Summary
    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76442 are related to issues with improper validation of specified quantity in input that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-1284.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-14 00:00 UTC
    CWE
    • CWE-1284 - Improper Validation of Specified Quantity in Input
    Impacted products
    Vendor Product Version
    Cisco Cisco Secure Email Affected: 14.0.0-698
    Affected: 13.5.1-277
    Affected: 13.0.0-392
    Affected: 14.2.0-620
    Affected: 13.0.5-007
    Affected: 13.5.4-038
    Affected: 14.2.1-020
    Affected: 14.3.0-032
    Affected: 15.0.0-104
    Affected: 15.0.1-030
    Affected: 15.5.0-048
    Affected: 15.5.1-055
    Affected: 15.5.2-018
    Affected: 16.0.0-050
    Affected: 15.0.3-002
    Affected: 16.0.0-054
    Affected: 15.5.3-022
    Affected: 16.0.1-017
    Affected: 15.5.4-012
    Affected: 16.0.4-016
    Affected: 15.0.5-016
    Affected: 16.0.2-112
    Affected: 16.0.3-044
    Affected: 16.5.0-780
    Create a notification for this product.
    Cisco Cisco Secure Email and Web Manager Affected: 13.6.2-023
    Affected: 13.6.2-078
    Affected: 13.0.0-249
    Affected: 13.0.0-277
    Affected: 13.8.1-052
    Affected: 13.8.1-068
    Affected: 13.8.1-074
    Affected: 14.0.0-404
    Affected: 12.8.1-002
    Affected: 14.1.0-227
    Affected: 13.6.1-201
    Affected: 14.2.0-203
    Affected: 14.2.0-212
    Affected: 12.8.1-021
    Affected: 13.8.1-108
    Affected: 14.2.0-224
    Affected: 14.3.0-120
    Affected: 15.0.0-334
    Affected: 15.5.1-024
    Affected: 15.5.1-029
    Affected: 15.5.2-005
    Affected: 16.0.0-195
    Affected: 15.5.3-017
    Affected: 16.0.1-010
    Affected: 15.0.1-035
    Affected: 16.0.2-088
    Affected: 15.5.4-007
    Affected: 15.0.2-007
    Affected: 16.0.4-010
    Affected: 16.0.3-016
    Affected: 16.5.0-429
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-76442",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-14T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-16T03:55:36.952Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "descriptions": [
              {
                "lang": "en",
                "value": "The CVE Program recognizes that this CVE Record provides vulnerability information that a Supplier CNA believes is very important to consumers. The CVE Program has flagged this CVE Record as it assigns a single CVE ID to a collection of individual vulnerabilities which does not align with CVE\u0027s \"one vulnerability, one ID\" principle, and therefore provides incomplete information. For further clarification, please see the CVE Program\u0027s blog, \"Preserving Vulnerability-Level Identification\" linked below. Details within the CNA container below are viewable by clicking on the CNA name."
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-15T17:03:58.176Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://www.cve.org/Media/News/item/blog/2026/06/16/Preserving-Vulnerability-Level-Identification"
              }
            ],
            "tags": [
              "x_bundling-flagged-by-CVE-Program"
            ]
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "Cisco Secure Email",
              "vendor": "Cisco",
              "versions": [
                {
                  "status": "affected",
                  "version": "14.0.0-698"
                },
                {
                  "status": "affected",
                  "version": "13.5.1-277"
                },
                {
                  "status": "affected",
                  "version": "13.0.0-392"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-620"
                },
                {
                  "status": "affected",
                  "version": "13.0.5-007"
                },
                {
                  "status": "affected",
                  "version": "13.5.4-038"
                },
                {
                  "status": "affected",
                  "version": "14.2.1-020"
                },
                {
                  "status": "affected",
                  "version": "14.3.0-032"
                },
                {
                  "status": "affected",
                  "version": "15.0.0-104"
                },
                {
                  "status": "affected",
                  "version": "15.0.1-030"
                },
                {
                  "status": "affected",
                  "version": "15.5.0-048"
                },
                {
                  "status": "affected",
                  "version": "15.5.1-055"
                },
                {
                  "status": "affected",
                  "version": "15.5.2-018"
                },
                {
                  "status": "affected",
                  "version": "16.0.0-050"
                },
                {
                  "status": "affected",
                  "version": "15.0.3-002"
                },
                {
                  "status": "affected",
                  "version": "16.0.0-054"
                },
                {
                  "status": "affected",
                  "version": "15.5.3-022"
                },
                {
                  "status": "affected",
                  "version": "16.0.1-017"
                },
                {
                  "status": "affected",
                  "version": "15.5.4-012"
                },
                {
                  "status": "affected",
                  "version": "16.0.4-016"
                },
                {
                  "status": "affected",
                  "version": "15.0.5-016"
                },
                {
                  "status": "affected",
                  "version": "16.0.2-112"
                },
                {
                  "status": "affected",
                  "version": "16.0.3-044"
                },
                {
                  "status": "affected",
                  "version": "16.5.0-780"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "Cisco Secure Email and Web Manager",
              "vendor": "Cisco",
              "versions": [
                {
                  "status": "affected",
                  "version": "13.6.2-023"
                },
                {
                  "status": "affected",
                  "version": "13.6.2-078"
                },
                {
                  "status": "affected",
                  "version": "13.0.0-249"
                },
                {
                  "status": "affected",
                  "version": "13.0.0-277"
                },
                {
                  "status": "affected",
                  "version": "13.8.1-052"
                },
                {
                  "status": "affected",
                  "version": "13.8.1-068"
                },
                {
                  "status": "affected",
                  "version": "13.8.1-074"
                },
                {
                  "status": "affected",
                  "version": "14.0.0-404"
                },
                {
                  "status": "affected",
                  "version": "12.8.1-002"
                },
                {
                  "status": "affected",
                  "version": "14.1.0-227"
                },
                {
                  "status": "affected",
                  "version": "13.6.1-201"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-203"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-212"
                },
                {
                  "status": "affected",
                  "version": "12.8.1-021"
                },
                {
                  "status": "affected",
                  "version": "13.8.1-108"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-224"
                },
                {
                  "status": "affected",
                  "version": "14.3.0-120"
                },
                {
                  "status": "affected",
                  "version": "15.0.0-334"
                },
                {
                  "status": "affected",
                  "version": "15.5.1-024"
                },
                {
                  "status": "affected",
                  "version": "15.5.1-029"
                },
                {
                  "status": "affected",
                  "version": "15.5.2-005"
                },
                {
                  "status": "affected",
                  "version": "16.0.0-195"
                },
                {
                  "status": "affected",
                  "version": "15.5.3-017"
                },
                {
                  "status": "affected",
                  "version": "16.0.1-010"
                },
                {
                  "status": "affected",
                  "version": "15.0.1-035"
                },
                {
                  "status": "affected",
                  "version": "16.0.2-088"
                },
                {
                  "status": "affected",
                  "version": "15.5.4-007"
                },
                {
                  "status": "affected",
                  "version": "15.0.2-007"
                },
                {
                  "status": "affected",
                  "version": "16.0.4-010"
                },
                {
                  "status": "affected",
                  "version": "16.0.3-016"
                },
                {
                  "status": "affected",
                  "version": "16.5.0-429"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "As part of Cisco\u0027s ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-76442 are related to issues with improper validation of specified quantity in input that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-1284."
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "value": "Except as otherwise noted previously, the Cisco PSIRT is not aware of any public announcements or malicious use of the vulnerabilities that are described in this advisory."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "cvssV3_1"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-1284",
                  "description": "Improper Validation of Specified Quantity in Input",
                  "lang": "en",
                  "type": "cwe"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-14T16:09:08.878Z",
            "orgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
            "shortName": "cisco"
          },
          "references": [
            {
              "name": "cisco-sa-hardening-esa-dfCrfXkm",
              "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm"
            }
          ],
          "source": {
            "advisory": "cisco-sa-hardening-esa-dfCrfXkm",
            "defects": [
              "CSCwu56549"
            ],
            "discovery": "INTERNAL"
          },
          "title": "Cisco Secure Email Gateway Security Hardening Release"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
        "assignerShortName": "cisco",
        "cveId": "CVE-2026-76442",
        "datePublished": "2026-09-14T16:09:08.878Z",
        "dateReserved": "2026-08-19T12:02:03.635Z",
        "dateUpdated": "2026-09-16T03:55:36.952Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-76440 (GCVE-0-2026-76440)

    Vulnerability from nvd – Published: 2026-09-14 16:08 – Updated: 2026-09-15 17:03
    VLAI
    Title
    Cisco Secure Email Gateway Security Hardening Release
    Summary
    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76440 are related to path traversal issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-23.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-14 00:00 UTC
    CWE
    • CWE-23 - Relative Path Traversal
    Impacted products
    Vendor Product Version
    Cisco Cisco Secure Email Affected: 14.0.0-698
    Affected: 13.5.1-277
    Affected: 13.0.0-392
    Affected: 14.2.0-620
    Affected: 13.0.5-007
    Affected: 13.5.4-038
    Affected: 14.2.1-020
    Affected: 14.3.0-032
    Affected: 15.0.0-104
    Affected: 15.0.1-030
    Affected: 15.5.0-048
    Affected: 15.5.1-055
    Affected: 15.5.2-018
    Affected: 16.0.0-050
    Affected: 15.0.3-002
    Affected: 16.0.0-054
    Affected: 15.5.3-022
    Affected: 16.0.1-017
    Affected: 15.5.4-012
    Affected: 16.0.4-016
    Affected: 15.0.5-016
    Affected: 16.0.2-112
    Affected: 16.0.3-044
    Affected: 15.5.5-014
    Create a notification for this product.
    Cisco Cisco Secure Email and Web Manager Affected: 13.6.2-023
    Affected: 13.6.2-078
    Affected: 13.0.0-249
    Affected: 13.0.0-277
    Affected: 13.8.1-052
    Affected: 13.8.1-068
    Affected: 13.8.1-074
    Affected: 14.0.0-404
    Affected: 12.8.1-002
    Affected: 14.1.0-227
    Affected: 13.6.1-201
    Affected: 14.2.0-203
    Affected: 14.2.0-212
    Affected: 12.8.1-021
    Affected: 13.8.1-108
    Affected: 14.2.0-224
    Affected: 14.3.0-120
    Affected: 15.0.0-334
    Affected: 15.5.1-024
    Affected: 15.5.1-029
    Affected: 15.5.2-005
    Affected: 16.0.0-195
    Affected: 15.5.3-017
    Affected: 16.0.1-010
    Affected: 15.0.1-035
    Affected: 16.0.2-088
    Affected: 15.5.4-007
    Affected: 15.0.2-007
    Affected: 16.0.4-010
    Affected: 16.0.3-016
    Affected: 16.5.0-429
    Affected: 15.5.5-006
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-76440",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-14T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-15T03:56:08.458Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "descriptions": [
              {
                "lang": "en",
                "value": "The CVE Program recognizes that this CVE Record provides vulnerability information that a Supplier CNA believes is very important to consumers. The CVE Program has flagged this CVE Record as it assigns a single CVE ID to a collection of individual vulnerabilities which does not align with CVE\u0027s \"one vulnerability, one ID\" principle, and therefore provides incomplete information. For further clarification, please see the CVE Program\u0027s blog, \"Preserving Vulnerability-Level Identification\" linked below. Details within the CNA container below are viewable by clicking on the CNA name."
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-15T17:03:57.728Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://www.cve.org/Media/News/item/blog/2026/06/16/Preserving-Vulnerability-Level-Identification"
              }
            ],
            "tags": [
              "x_bundling-flagged-by-CVE-Program"
            ]
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "Cisco Secure Email",
              "vendor": "Cisco",
              "versions": [
                {
                  "status": "affected",
                  "version": "14.0.0-698"
                },
                {
                  "status": "affected",
                  "version": "13.5.1-277"
                },
                {
                  "status": "affected",
                  "version": "13.0.0-392"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-620"
                },
                {
                  "status": "affected",
                  "version": "13.0.5-007"
                },
                {
                  "status": "affected",
                  "version": "13.5.4-038"
                },
                {
                  "status": "affected",
                  "version": "14.2.1-020"
                },
                {
                  "status": "affected",
                  "version": "14.3.0-032"
                },
                {
                  "status": "affected",
                  "version": "15.0.0-104"
                },
                {
                  "status": "affected",
                  "version": "15.0.1-030"
                },
                {
                  "status": "affected",
                  "version": "15.5.0-048"
                },
                {
                  "status": "affected",
                  "version": "15.5.1-055"
                },
                {
                  "status": "affected",
                  "version": "15.5.2-018"
                },
                {
                  "status": "affected",
                  "version": "16.0.0-050"
                },
                {
                  "status": "affected",
                  "version": "15.0.3-002"
                },
                {
                  "status": "affected",
                  "version": "16.0.0-054"
                },
                {
                  "status": "affected",
                  "version": "15.5.3-022"
                },
                {
                  "status": "affected",
                  "version": "16.0.1-017"
                },
                {
                  "status": "affected",
                  "version": "15.5.4-012"
                },
                {
                  "status": "affected",
                  "version": "16.0.4-016"
                },
                {
                  "status": "affected",
                  "version": "15.0.5-016"
                },
                {
                  "status": "affected",
                  "version": "16.0.2-112"
                },
                {
                  "status": "affected",
                  "version": "16.0.3-044"
                },
                {
                  "status": "affected",
                  "version": "15.5.5-014"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "Cisco Secure Email and Web Manager",
              "vendor": "Cisco",
              "versions": [
                {
                  "status": "affected",
                  "version": "13.6.2-023"
                },
                {
                  "status": "affected",
                  "version": "13.6.2-078"
                },
                {
                  "status": "affected",
                  "version": "13.0.0-249"
                },
                {
                  "status": "affected",
                  "version": "13.0.0-277"
                },
                {
                  "status": "affected",
                  "version": "13.8.1-052"
                },
                {
                  "status": "affected",
                  "version": "13.8.1-068"
                },
                {
                  "status": "affected",
                  "version": "13.8.1-074"
                },
                {
                  "status": "affected",
                  "version": "14.0.0-404"
                },
                {
                  "status": "affected",
                  "version": "12.8.1-002"
                },
                {
                  "status": "affected",
                  "version": "14.1.0-227"
                },
                {
                  "status": "affected",
                  "version": "13.6.1-201"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-203"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-212"
                },
                {
                  "status": "affected",
                  "version": "12.8.1-021"
                },
                {
                  "status": "affected",
                  "version": "13.8.1-108"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-224"
                },
                {
                  "status": "affected",
                  "version": "14.3.0-120"
                },
                {
                  "status": "affected",
                  "version": "15.0.0-334"
                },
                {
                  "status": "affected",
                  "version": "15.5.1-024"
                },
                {
                  "status": "affected",
                  "version": "15.5.1-029"
                },
                {
                  "status": "affected",
                  "version": "15.5.2-005"
                },
                {
                  "status": "affected",
                  "version": "16.0.0-195"
                },
                {
                  "status": "affected",
                  "version": "15.5.3-017"
                },
                {
                  "status": "affected",
                  "version": "16.0.1-010"
                },
                {
                  "status": "affected",
                  "version": "15.0.1-035"
                },
                {
                  "status": "affected",
                  "version": "16.0.2-088"
                },
                {
                  "status": "affected",
                  "version": "15.5.4-007"
                },
                {
                  "status": "affected",
                  "version": "15.0.2-007"
                },
                {
                  "status": "affected",
                  "version": "16.0.4-010"
                },
                {
                  "status": "affected",
                  "version": "16.0.3-016"
                },
                {
                  "status": "affected",
                  "version": "16.5.0-429"
                },
                {
                  "status": "affected",
                  "version": "15.5.5-006"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "As part of Cisco\u0027s ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-76440 are related to path traversal issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-23."
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "value": "Except as otherwise noted previously, the Cisco PSIRT is not aware of any public announcements or malicious use of the vulnerabilities that are described in this advisory."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "cvssV3_1"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-23",
                  "description": "Relative Path Traversal",
                  "lang": "en",
                  "type": "cwe"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-14T16:08:50.075Z",
            "orgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
            "shortName": "cisco"
          },
          "references": [
            {
              "name": "cisco-sa-hardening-esa-dfCrfXkm",
              "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm"
            }
          ],
          "source": {
            "advisory": "cisco-sa-hardening-esa-dfCrfXkm",
            "defects": [
              "CSCwu56221"
            ],
            "discovery": "INTERNAL"
          },
          "title": "Cisco Secure Email Gateway Security Hardening Release"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
        "assignerShortName": "cisco",
        "cveId": "CVE-2026-76440",
        "datePublished": "2026-09-14T16:08:50.075Z",
        "dateReserved": "2026-08-19T12:02:03.635Z",
        "dateUpdated": "2026-09-15T17:03:57.728Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-20353 (GCVE-0-2026-20353)

    Vulnerability from nvd – Published: 2026-09-14 16:08 – Updated: 2026-09-15 17:03
    VLAI
    Title
    Cisco Secure Email Gateway Security Hardening Release
    Summary
    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20353 are related to issues with improper control of a resource through its lifetime that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-664.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-14 00:00 UTC
    CWE
    • CWE-664 - Improper Control of a Resource Through its Lifetime
    Impacted products
    Vendor Product Version
    Cisco Cisco Secure Email Affected: 14.0.0-698
    Affected: 13.5.1-277
    Affected: 13.0.0-392
    Affected: 14.2.0-620
    Affected: 13.0.5-007
    Affected: 13.5.4-038
    Affected: 14.2.1-020
    Affected: 14.3.0-032
    Affected: 15.0.0-104
    Affected: 15.0.1-030
    Affected: 15.5.0-048
    Affected: 15.5.1-055
    Affected: 15.5.2-018
    Affected: 16.0.0-050
    Affected: 15.0.3-002
    Affected: 16.0.0-054
    Affected: 15.5.3-022
    Affected: 16.0.1-017
    Affected: 15.5.4-012
    Affected: 16.0.4-016
    Affected: 15.0.5-016
    Affected: 16.0.2-112
    Affected: 16.0.3-044
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-20353",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-14T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-15T03:56:07.357Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "descriptions": [
              {
                "lang": "en",
                "value": "The CVE Program recognizes that this CVE Record provides vulnerability information that a Supplier CNA believes is very important to consumers. The CVE Program has flagged this CVE Record as it assigns a single CVE ID to a collection of individual vulnerabilities which does not align with CVE\u0027s \"one vulnerability, one ID\" principle, and therefore provides incomplete information. For further clarification, please see the CVE Program\u0027s blog, \"Preserving Vulnerability-Level Identification\" linked below. Details within the CNA container below are viewable by clicking on the CNA name."
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-15T17:03:57.940Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://www.cve.org/Media/News/item/blog/2026/06/16/Preserving-Vulnerability-Level-Identification"
              }
            ],
            "tags": [
              "x_bundling-flagged-by-CVE-Program"
            ]
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "Cisco Secure Email",
              "vendor": "Cisco",
              "versions": [
                {
                  "status": "affected",
                  "version": "14.0.0-698"
                },
                {
                  "status": "affected",
                  "version": "13.5.1-277"
                },
                {
                  "status": "affected",
                  "version": "13.0.0-392"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-620"
                },
                {
                  "status": "affected",
                  "version": "13.0.5-007"
                },
                {
                  "status": "affected",
                  "version": "13.5.4-038"
                },
                {
                  "status": "affected",
                  "version": "14.2.1-020"
                },
                {
                  "status": "affected",
                  "version": "14.3.0-032"
                },
                {
                  "status": "affected",
                  "version": "15.0.0-104"
                },
                {
                  "status": "affected",
                  "version": "15.0.1-030"
                },
                {
                  "status": "affected",
                  "version": "15.5.0-048"
                },
                {
                  "status": "affected",
                  "version": "15.5.1-055"
                },
                {
                  "status": "affected",
                  "version": "15.5.2-018"
                },
                {
                  "status": "affected",
                  "version": "16.0.0-050"
                },
                {
                  "status": "affected",
                  "version": "15.0.3-002"
                },
                {
                  "status": "affected",
                  "version": "16.0.0-054"
                },
                {
                  "status": "affected",
                  "version": "15.5.3-022"
                },
                {
                  "status": "affected",
                  "version": "16.0.1-017"
                },
                {
                  "status": "affected",
                  "version": "15.5.4-012"
                },
                {
                  "status": "affected",
                  "version": "16.0.4-016"
                },
                {
                  "status": "affected",
                  "version": "15.0.5-016"
                },
                {
                  "status": "affected",
                  "version": "16.0.2-112"
                },
                {
                  "status": "affected",
                  "version": "16.0.3-044"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "As part of Cisco\u0027s ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-20353 are related to issues with improper control of a resource through its lifetime that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-664."
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "value": "Except as otherwise noted previously, the Cisco PSIRT is not aware of any public announcements or malicious use of the vulnerabilities that are described in this advisory."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "cvssV3_1"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-664",
                  "description": "Improper Control of a Resource Through its Lifetime",
                  "lang": "en",
                  "type": "cwe"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-14T16:08:50.062Z",
            "orgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
            "shortName": "cisco"
          },
          "references": [
            {
              "name": "cisco-sa-hardening-esa-dfCrfXkm",
              "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm"
            }
          ],
          "source": {
            "advisory": "cisco-sa-hardening-esa-dfCrfXkm",
            "defects": [
              "CSCwu68894"
            ],
            "discovery": "INTERNAL"
          },
          "title": "Cisco Secure Email Gateway Security Hardening Release"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
        "assignerShortName": "cisco",
        "cveId": "CVE-2026-20353",
        "datePublished": "2026-09-14T16:08:50.062Z",
        "dateReserved": "2025-10-08T11:59:15.414Z",
        "dateUpdated": "2026-09-15T17:03:57.940Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-20355 (GCVE-0-2026-20355)

    Vulnerability from nvd – Published: 2026-09-02 16:14 – Updated: 2026-09-08 16:04
    VLAI
    Title
    Cisco Secure Email S/MIME Ciphertext Decryption Vulnerabilty
    Summary
    Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages. These vulnerabilities are due to insufficient validation of message integrity. An attacker could exploit these vulnerabilities by using a machine-in-the-middle technique to intercept and modify traffic between email gateways. A successful exploit could allow the attacker to obtain plaintext content from the encrypted communication.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-02 16:49 UTC
    CWE
    • CWE-345 - Insufficient Verification of Data Authenticity
    Impacted products
    Vendor Product Version
    Cisco Cisco Secure Email Affected: 14.0.0-698
    Affected: 13.5.1-277
    Affected: 13.0.0-392
    Affected: 14.2.0-620
    Affected: 13.0.5-007
    Affected: 13.5.4-038
    Affected: 14.2.1-020
    Affected: 14.3.0-032
    Affected: 15.0.0-104
    Affected: 15.0.1-030
    Affected: 15.5.0-048
    Affected: 15.5.1-055
    Affected: 15.5.2-018
    Affected: 16.0.0-050
    Affected: 15.0.3-002
    Affected: 16.0.0-054
    Affected: 15.5.3-022
    Affected: 16.0.1-017
    Affected: 15.5.4-012
    Affected: 16.0.4-016
    Affected: 15.0.5-016
    Affected: 16.0.2-112
    Affected: 16.0.3-044
    Affected: 16.5.0-780
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-20355",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-02T16:49:13.406894Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-02T17:58:57.899Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "Cisco Secure Email",
              "vendor": "Cisco",
              "versions": [
                {
                  "status": "affected",
                  "version": "14.0.0-698"
                },
                {
                  "status": "affected",
                  "version": "13.5.1-277"
                },
                {
                  "status": "affected",
                  "version": "13.0.0-392"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-620"
                },
                {
                  "status": "affected",
                  "version": "13.0.5-007"
                },
                {
                  "status": "affected",
                  "version": "13.5.4-038"
                },
                {
                  "status": "affected",
                  "version": "14.2.1-020"
                },
                {
                  "status": "affected",
                  "version": "14.3.0-032"
                },
                {
                  "status": "affected",
                  "version": "15.0.0-104"
                },
                {
                  "status": "affected",
                  "version": "15.0.1-030"
                },
                {
                  "status": "affected",
                  "version": "15.5.0-048"
                },
                {
                  "status": "affected",
                  "version": "15.5.1-055"
                },
                {
                  "status": "affected",
                  "version": "15.5.2-018"
                },
                {
                  "status": "affected",
                  "version": "16.0.0-050"
                },
                {
                  "status": "affected",
                  "version": "15.0.3-002"
                },
                {
                  "status": "affected",
                  "version": "16.0.0-054"
                },
                {
                  "status": "affected",
                  "version": "15.5.3-022"
                },
                {
                  "status": "affected",
                  "version": "16.0.1-017"
                },
                {
                  "status": "affected",
                  "version": "15.5.4-012"
                },
                {
                  "status": "affected",
                  "version": "16.0.4-016"
                },
                {
                  "status": "affected",
                  "version": "15.0.5-016"
                },
                {
                  "status": "affected",
                  "version": "16.0.2-112"
                },
                {
                  "status": "affected",
                  "version": "16.0.3-044"
                },
                {
                  "status": "affected",
                  "version": "16.5.0-780"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages.\r\n\r\nThese vulnerabilities are due to insufficient validation of message integrity. An attacker could exploit these vulnerabilities by using a machine-in-the-middle technique to intercept and modify traffic between email gateways. A successful exploit could allow the attacker to obtain plaintext content from the encrypted communication."
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "value": "The Cisco Product Security Incident Response Team (PSIRT) is aware that a public announcement is available for the vulnerabilities that are described in this advisory.\r\n\r\nThe Cisco PSIRT is not aware of any malicious use of the vulnerabilities that are described in this advisory."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.9,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "cvssV3_1"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-345",
                  "description": "Insufficient Verification of Data Authenticity",
                  "lang": "en",
                  "type": "cwe"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-08T16:04:40.505Z",
            "orgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
            "shortName": "cisco"
          },
          "references": [
            {
              "name": "cisco-sa-esa-smime-disc-dzw4rEdY",
              "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-smime-disc-dzw4rEdY"
            }
          ],
          "source": {
            "advisory": "cisco-sa-esa-smime-disc-dzw4rEdY",
            "defects": [
              "CSCwu28362"
            ],
            "discovery": "EXTERNAL"
          },
          "title": "Cisco Secure Email S/MIME Ciphertext Decryption Vulnerabilty"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
        "assignerShortName": "cisco",
        "cveId": "CVE-2026-20355",
        "datePublished": "2026-09-02T16:14:32.732Z",
        "dateReserved": "2025-10-08T11:59:15.414Z",
        "dateUpdated": "2026-09-08T16:04:40.505Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-20354 (GCVE-0-2026-20354)

    Vulnerability from nvd – Published: 2026-09-02 16:14 – Updated: 2026-09-02 17:58
    VLAI
    Title
    Cisco Secure Email S/MIME Ciphertext Decryption Vulnerabilty
    Summary
    Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages. These vulnerabilities are due to insufficient validation of message integrity. An attacker could exploit these vulnerabilities by using a machine-in-the-middle technique to intercept and modify traffic between email gateways. A successful exploit could allow the attacker to obtain plaintext content from the encrypted communication.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-02 16:49 UTC
    CWE
    • CWE-354 - Improper Validation of Integrity Check Value
    Impacted products
    Vendor Product Version
    Cisco Cisco Secure Email Affected: 14.0.0-698
    Affected: 13.5.1-277
    Affected: 13.0.0-392
    Affected: 14.2.0-620
    Affected: 13.0.5-007
    Affected: 13.5.4-038
    Affected: 14.2.1-020
    Affected: 14.3.0-032
    Affected: 15.0.0-104
    Affected: 15.0.1-030
    Affected: 15.5.0-048
    Affected: 15.5.1-055
    Affected: 15.5.2-018
    Affected: 16.0.0-050
    Affected: 15.0.3-002
    Affected: 16.0.0-054
    Affected: 15.5.3-022
    Affected: 16.0.1-017
    Affected: 15.5.4-012
    Affected: 16.0.4-016
    Affected: 15.0.5-016
    Affected: 16.0.2-112
    Affected: 16.0.3-044
    Affected: 16.5.0-780
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-20354",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-02T16:49:02.578484Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-02T17:58:58.074Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "Cisco Secure Email",
              "vendor": "Cisco",
              "versions": [
                {
                  "status": "affected",
                  "version": "14.0.0-698"
                },
                {
                  "status": "affected",
                  "version": "13.5.1-277"
                },
                {
                  "status": "affected",
                  "version": "13.0.0-392"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-620"
                },
                {
                  "status": "affected",
                  "version": "13.0.5-007"
                },
                {
                  "status": "affected",
                  "version": "13.5.4-038"
                },
                {
                  "status": "affected",
                  "version": "14.2.1-020"
                },
                {
                  "status": "affected",
                  "version": "14.3.0-032"
                },
                {
                  "status": "affected",
                  "version": "15.0.0-104"
                },
                {
                  "status": "affected",
                  "version": "15.0.1-030"
                },
                {
                  "status": "affected",
                  "version": "15.5.0-048"
                },
                {
                  "status": "affected",
                  "version": "15.5.1-055"
                },
                {
                  "status": "affected",
                  "version": "15.5.2-018"
                },
                {
                  "status": "affected",
                  "version": "16.0.0-050"
                },
                {
                  "status": "affected",
                  "version": "15.0.3-002"
                },
                {
                  "status": "affected",
                  "version": "16.0.0-054"
                },
                {
                  "status": "affected",
                  "version": "15.5.3-022"
                },
                {
                  "status": "affected",
                  "version": "16.0.1-017"
                },
                {
                  "status": "affected",
                  "version": "15.5.4-012"
                },
                {
                  "status": "affected",
                  "version": "16.0.4-016"
                },
                {
                  "status": "affected",
                  "version": "15.0.5-016"
                },
                {
                  "status": "affected",
                  "version": "16.0.2-112"
                },
                {
                  "status": "affected",
                  "version": "16.0.3-044"
                },
                {
                  "status": "affected",
                  "version": "16.5.0-780"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages.\r\n\r\nThese vulnerabilities are due to insufficient validation of message integrity. An attacker could exploit these vulnerabilities by using a machine-in-the-middle technique to intercept and modify traffic between email gateways. A successful exploit could allow the attacker to obtain plaintext content from the encrypted communication."
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "value": "The Cisco Product Security Incident Response Team (PSIRT) is aware that a public announcement is available for the vulnerabilities that are described in this advisory.\r\n\r\nThe Cisco PSIRT is not aware of any malicious use of the vulnerabilities that are described in this advisory."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.9,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "cvssV3_1"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-354",
                  "description": "Improper Validation of Integrity Check Value",
                  "lang": "en",
                  "type": "cwe"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-02T16:14:29.829Z",
            "orgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
            "shortName": "cisco"
          },
          "references": [
            {
              "name": "cisco-sa-esa-smime-disc-dzw4rEdY",
              "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-smime-disc-dzw4rEdY"
            }
          ],
          "source": {
            "advisory": "cisco-sa-esa-smime-disc-dzw4rEdY",
            "defects": [
              "CSCwu28364"
            ],
            "discovery": "EXTERNAL"
          },
          "title": "Cisco Secure Email S/MIME Ciphertext Decryption Vulnerabilty"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
        "assignerShortName": "cisco",
        "cveId": "CVE-2026-20354",
        "datePublished": "2026-09-02T16:14:29.829Z",
        "dateReserved": "2025-10-08T11:59:15.414Z",
        "dateUpdated": "2026-09-02T17:58:58.074Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-20393 (GCVE-0-2025-20393)

    Vulnerability from nvd – Published: 2025-12-17 16:47 – Updated: 2026-02-26 16:07
    VLAI CISA Previdian
    Title
    Cisco Secure Email Gateway and Cisco Secure Email and Web Manager Remote Command Execution Vulnerability
    Summary
    A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to execute arbitrary system commands on an affected device with root privileges. This vulnerability is due to insufficient validation of HTTP requests by the Spam Quarantine feature. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with root privileges.
    SSVC
    Exploitation: active Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-12-18 04:55 UTC
    CWE
    • CWE-20 - Improper Input Validation
    Impacted products
    Vendor Product Version
    Cisco Cisco Secure Email Affected: 14.0.0-698
    Affected: 13.5.1-277
    Affected: 13.0.0-392
    Affected: 14.2.0-620
    Affected: 13.0.5-007
    Affected: 13.5.4-038
    Affected: 14.2.1-020
    Affected: 14.3.0-032
    Affected: 15.0.0-104
    Affected: 15.0.1-030
    Affected: 15.5.0-048
    Affected: 15.5.1-055
    Affected: 15.5.2-018
    Affected: 16.0.0-050
    Affected: 15.0.3-002
    Affected: 16.0.0-054
    Affected: 15.5.3-022
    Affected: 16.0.1-017
    Create a notification for this product.
    Cisco Cisco Secure Email and Web Manager Affected: 13.6.2-023
    Affected: 13.6.2-078
    Affected: 13.0.0-249
    Affected: 13.0.0-277
    Affected: 13.8.1-052
    Affected: 13.8.1-068
    Affected: 13.8.1-074
    Affected: 14.0.0-404
    Affected: 12.8.1-002
    Affected: 14.1.0-227
    Affected: 13.6.1-201
    Affected: 14.2.0-203
    Affected: 14.2.0-212
    Affected: 12.8.1-021
    Affected: 13.8.1-108
    Affected: 14.2.0-224
    Affected: 14.3.0-120
    Affected: 15.0.0-334
    Affected: 15.5.1-024
    Affected: 15.5.1-029
    Affected: 15.5.2-005
    Affected: 16.0.0-195
    Affected: 15.5.3-017
    Affected: 16.0.1-010
    Affected: 15.0.1-035
    Affected: 16.0.2-088
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-20393",
                    "options": [
                      {
                        "Exploitation": "active"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-12-18T04:55:22.327258Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              },
              {
                "other": {
                  "content": {
                    "dateAdded": "2025-12-17",
                    "reference": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-20393"
                  },
                  "type": "kev"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-02-26T16:07:31.045Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "government-resource"
                ],
                "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-20393"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "Cisco Secure Email",
              "vendor": "Cisco",
              "versions": [
                {
                  "status": "affected",
                  "version": "14.0.0-698"
                },
                {
                  "status": "affected",
                  "version": "13.5.1-277"
                },
                {
                  "status": "affected",
                  "version": "13.0.0-392"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-620"
                },
                {
                  "status": "affected",
                  "version": "13.0.5-007"
                },
                {
                  "status": "affected",
                  "version": "13.5.4-038"
                },
                {
                  "status": "affected",
                  "version": "14.2.1-020"
                },
                {
                  "status": "affected",
                  "version": "14.3.0-032"
                },
                {
                  "status": "affected",
                  "version": "15.0.0-104"
                },
                {
                  "status": "affected",
                  "version": "15.0.1-030"
                },
                {
                  "status": "affected",
                  "version": "15.5.0-048"
                },
                {
                  "status": "affected",
                  "version": "15.5.1-055"
                },
                {
                  "status": "affected",
                  "version": "15.5.2-018"
                },
                {
                  "status": "affected",
                  "version": "16.0.0-050"
                },
                {
                  "status": "affected",
                  "version": "15.0.3-002"
                },
                {
                  "status": "affected",
                  "version": "16.0.0-054"
                },
                {
                  "status": "affected",
                  "version": "15.5.3-022"
                },
                {
                  "status": "affected",
                  "version": "16.0.1-017"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "Cisco Secure Email and Web Manager",
              "vendor": "Cisco",
              "versions": [
                {
                  "status": "affected",
                  "version": "13.6.2-023"
                },
                {
                  "status": "affected",
                  "version": "13.6.2-078"
                },
                {
                  "status": "affected",
                  "version": "13.0.0-249"
                },
                {
                  "status": "affected",
                  "version": "13.0.0-277"
                },
                {
                  "status": "affected",
                  "version": "13.8.1-052"
                },
                {
                  "status": "affected",
                  "version": "13.8.1-068"
                },
                {
                  "status": "affected",
                  "version": "13.8.1-074"
                },
                {
                  "status": "affected",
                  "version": "14.0.0-404"
                },
                {
                  "status": "affected",
                  "version": "12.8.1-002"
                },
                {
                  "status": "affected",
                  "version": "14.1.0-227"
                },
                {
                  "status": "affected",
                  "version": "13.6.1-201"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-203"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-212"
                },
                {
                  "status": "affected",
                  "version": "12.8.1-021"
                },
                {
                  "status": "affected",
                  "version": "13.8.1-108"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-224"
                },
                {
                  "status": "affected",
                  "version": "14.3.0-120"
                },
                {
                  "status": "affected",
                  "version": "15.0.0-334"
                },
                {
                  "status": "affected",
                  "version": "15.5.1-024"
                },
                {
                  "status": "affected",
                  "version": "15.5.1-029"
                },
                {
                  "status": "affected",
                  "version": "15.5.2-005"
                },
                {
                  "status": "affected",
                  "version": "16.0.0-195"
                },
                {
                  "status": "affected",
                  "version": "15.5.3-017"
                },
                {
                  "status": "affected",
                  "version": "16.0.1-010"
                },
                {
                  "status": "affected",
                  "version": "15.0.1-035"
                },
                {
                  "status": "affected",
                  "version": "16.0.2-088"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to execute arbitrary system commands on an affected device with root privileges.\r\n\r\nThis vulnerability is due to insufficient validation of HTTP requests by the Spam Quarantine feature. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with\u0026nbsp;root privileges."
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "value": "In December 2025, the Cisco Product Security Incident Response Team (PSIRT) became aware of potentially malicious activity that targets Cisco Secure Email Gateway and Cisco Secure Email and Web Manager appliances."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 10,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "cvssV3_1"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-20",
                  "description": "Improper Input Validation",
                  "lang": "en",
                  "type": "cwe"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-01-15T16:32:03.740Z",
            "orgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
            "shortName": "cisco"
          },
          "references": [
            {
              "name": "cisco-sa-sma-attack-N9bf4",
              "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sma-attack-N9bf4"
            }
          ],
          "source": {
            "advisory": "cisco-sa-sma-attack-N9bf4",
            "defects": [
              "CSCws36549"
            ],
            "discovery": "EXTERNAL"
          },
          "title": "Cisco Secure Email Gateway and Cisco Secure Email and Web Manager Remote Command Execution Vulnerability"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
        "assignerShortName": "cisco",
        "cveId": "CVE-2025-20393",
        "datePublished": "2025-12-17T16:47:13.128Z",
        "dateReserved": "2024-10-10T19:15:13.266Z",
        "dateUpdated": "2026-02-26T16:07:31.045Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-20153 (GCVE-0-2025-20153)

    Vulnerability from nvd – Published: 2025-02-19 16:06 – Updated: 2025-02-19 16:19
    VLAI
    Title
    Cisco ESA mail Bypass
    Summary
    A vulnerability in the email filtering mechanism of Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to bypass the configured rules and allow emails that should have been denied to flow through an affected device.   This vulnerability is due to improper handling of email that passes through an affected device. An attacker could exploit this vulnerability by sending a crafted email through the affected device. A successful exploit could allow the attacker to bypass email filters on the affected device.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-02-19 16:19 UTC
    CWE
    • CWE-284 - Improper Access Control
    Impacted products
    Vendor Product Version
    Cisco Cisco Secure Email Affected: 14.0.0-698
    Affected: 13.5.1-277
    Affected: 13.0.0-392
    Affected: 14.2.0-620
    Affected: 13.0.5-007
    Affected: 13.5.4-038
    Affected: 14.2.1-020
    Affected: 14.3.0-032
    Affected: 15.0.0-104
    Affected: 15.0.1-030
    Affected: 15.5.0-048
    Affected: 15.5.1-055
    Affected: 15.5.2-018
    Affected: 16.0.0-050
    Affected: 15.0.3-002
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-20153",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-02-19T16:19:02.308539Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-02-19T16:19:19.168Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "Cisco Secure Email",
              "vendor": "Cisco",
              "versions": [
                {
                  "status": "affected",
                  "version": "14.0.0-698"
                },
                {
                  "status": "affected",
                  "version": "13.5.1-277"
                },
                {
                  "status": "affected",
                  "version": "13.0.0-392"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-620"
                },
                {
                  "status": "affected",
                  "version": "13.0.5-007"
                },
                {
                  "status": "affected",
                  "version": "13.5.4-038"
                },
                {
                  "status": "affected",
                  "version": "14.2.1-020"
                },
                {
                  "status": "affected",
                  "version": "14.3.0-032"
                },
                {
                  "status": "affected",
                  "version": "15.0.0-104"
                },
                {
                  "status": "affected",
                  "version": "15.0.1-030"
                },
                {
                  "status": "affected",
                  "version": "15.5.0-048"
                },
                {
                  "status": "affected",
                  "version": "15.5.1-055"
                },
                {
                  "status": "affected",
                  "version": "15.5.2-018"
                },
                {
                  "status": "affected",
                  "version": "16.0.0-050"
                },
                {
                  "status": "affected",
                  "version": "15.0.3-002"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability in the email filtering mechanism of Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to bypass the configured rules and allow emails that should have been denied to flow through an affected device. \u0026nbsp;\r\n\r\nThis vulnerability is due to improper handling of email that passes through an affected device. An attacker could exploit this vulnerability by sending a crafted email through the affected device. A successful exploit could allow the attacker to bypass email filters on the affected device."
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "value": "The Cisco PSIRT is not aware of any public announcements or malicious use of the vulnerability that is described in this advisory."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.8,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N",
                "version": "3.1"
              },
              "format": "cvssV3_1"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-284",
                  "description": "Improper Access Control",
                  "lang": "en",
                  "type": "cwe"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-02-19T16:06:10.664Z",
            "orgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
            "shortName": "cisco"
          },
          "references": [
            {
              "name": "cisco-sa-esa-mailpol-bypass-5nVcJZMw",
              "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-mailpol-bypass-5nVcJZMw"
            }
          ],
          "source": {
            "advisory": "cisco-sa-esa-mailpol-bypass-5nVcJZMw",
            "defects": [
              "CSCwm82380"
            ],
            "discovery": "INTERNAL"
          },
          "title": "Cisco ESA mail Bypass"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
        "assignerShortName": "cisco",
        "cveId": "CVE-2025-20153",
        "datePublished": "2025-02-19T16:06:10.664Z",
        "dateReserved": "2024-10-10T19:15:13.216Z",
        "dateUpdated": "2025-02-19T16:19:19.168Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2025-20207 (GCVE-0-2025-20207)

    Vulnerability from nvd – Published: 2025-02-05 16:15 – Updated: 2025-02-05 16:57
    VLAI
    Title
    Cisco Secure Email Gateway, Cisco Secure Email and Web Appliance and Cisco Secure Web Appliance SNMP Polling Information Disclosure Vulnerability
    Summary
    A vulnerability in Simple Network Management Protocol (SNMP) polling for Cisco Secure Email and Web Manager, Cisco Secure Email Gateway, and Cisco Secure Web Appliance could allow an authenticated, remote attacker to obtain confidential information about the underlying operating system. This vulnerability exists because the appliances do not protect confidential information at rest in response to SNMP poll requests. An attacker could exploit this vulnerability by sending a crafted SNMP poll request to the affected appliance. A successful exploit could allow the attacker to discover confidential information that should be restricted. To exploit this vulnerability, an attacker must have the configured SNMP credentials.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-02-05 16:57 UTC
    CWE
    • CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor
    Impacted products
    Vendor Product Version
    Cisco Cisco Secure Email Affected: 14.0.0-698
    Affected: 13.5.1-277
    Affected: 13.0.0-392
    Affected: 14.2.0-620
    Affected: 13.0.5-007
    Affected: 13.5.4-038
    Affected: 14.2.1-020
    Affected: 14.3.0-032
    Affected: 15.0.0-104
    Affected: 15.0.1-030
    Affected: 15.5.0-048
    Affected: 15.5.1-055
    Create a notification for this product.
    Cisco Cisco Secure Email and Web Manager Affected: 13.6.2-023
    Affected: 13.6.2-078
    Affected: 13.0.0-249
    Affected: 13.0.0-277
    Affected: 13.8.1-052
    Affected: 13.8.1-068
    Affected: 13.8.1-074
    Affected: 14.0.0-404
    Affected: 12.8.1-002
    Affected: 14.1.0-227
    Affected: 13.6.1-201
    Affected: 14.2.0-203
    Affected: 14.2.0-212
    Affected: 12.8.1-021
    Affected: 13.8.1-108
    Affected: 14.2.0-224
    Affected: 14.3.0-120
    Affected: 15.0.0-334
    Affected: 15.5.1-024
    Affected: 15.5.1-029
    Create a notification for this product.
    Cisco Cisco Secure Web Appliance Affected: 11.8.0-453
    Affected: 12.5.3-002
    Affected: 12.0.3-007
    Affected: 12.0.3-005
    Affected: 14.1.0-032
    Affected: 14.1.0-047
    Affected: 14.1.0-041
    Affected: 12.0.4-002
    Affected: 14.0.2-012
    Affected: 11.8.0-414
    Affected: 12.0.1-268
    Affected: 11.8.1-023
    Affected: 11.8.3-021
    Affected: 11.8.3-018
    Affected: 12.5.1-011
    Affected: 11.8.4-004
    Affected: 12.5.2-007
    Affected: 12.5.2-011
    Affected: 14.5.0-498
    Affected: 12.5.4-005
    Affected: 12.5.4-011
    Affected: 12.0.5-011
    Affected: 14.0.3-014
    Affected: 12.5.5-004
    Affected: 12.5.5-005
    Affected: 12.5.5-008
    Affected: 14.0.4-005
    Affected: 14.5.1-008
    Affected: 14.5.1-016
    Affected: 15.0.0-355
    Affected: 15.0.0-322
    Affected: 12.5.6-008
    Affected: 15.1.0-287
    Affected: 14.5.2-011
    Affected: 15.2.0-116
    Affected: 14.0.5-007
    Affected: 15.2.0-164
    Affected: 14.5.1-510
    Affected: 12.0.2-012
    Affected: 12.0.2-004
    Affected: 14.5.1-607
    Affected: 14.5.3-033
    Affected: 12.0.1-334
    Affected: 14.0.1-503
    Affected: 14.0.1-053
    Affected: 11.8.0-429
    Affected: 14.0.1-040
    Affected: 14.0.1-014
    Affected: 12.5.1-043
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-20207",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-02-05T16:57:37.294661Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-02-05T16:57:53.809Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "Cisco Secure Email",
              "vendor": "Cisco",
              "versions": [
                {
                  "status": "affected",
                  "version": "14.0.0-698"
                },
                {
                  "status": "affected",
                  "version": "13.5.1-277"
                },
                {
                  "status": "affected",
                  "version": "13.0.0-392"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-620"
                },
                {
                  "status": "affected",
                  "version": "13.0.5-007"
                },
                {
                  "status": "affected",
                  "version": "13.5.4-038"
                },
                {
                  "status": "affected",
                  "version": "14.2.1-020"
                },
                {
                  "status": "affected",
                  "version": "14.3.0-032"
                },
                {
                  "status": "affected",
                  "version": "15.0.0-104"
                },
                {
                  "status": "affected",
                  "version": "15.0.1-030"
                },
                {
                  "status": "affected",
                  "version": "15.5.0-048"
                },
                {
                  "status": "affected",
                  "version": "15.5.1-055"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "Cisco Secure Email and Web Manager",
              "vendor": "Cisco",
              "versions": [
                {
                  "status": "affected",
                  "version": "13.6.2-023"
                },
                {
                  "status": "affected",
                  "version": "13.6.2-078"
                },
                {
                  "status": "affected",
                  "version": "13.0.0-249"
                },
                {
                  "status": "affected",
                  "version": "13.0.0-277"
                },
                {
                  "status": "affected",
                  "version": "13.8.1-052"
                },
                {
                  "status": "affected",
                  "version": "13.8.1-068"
                },
                {
                  "status": "affected",
                  "version": "13.8.1-074"
                },
                {
                  "status": "affected",
                  "version": "14.0.0-404"
                },
                {
                  "status": "affected",
                  "version": "12.8.1-002"
                },
                {
                  "status": "affected",
                  "version": "14.1.0-227"
                },
                {
                  "status": "affected",
                  "version": "13.6.1-201"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-203"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-212"
                },
                {
                  "status": "affected",
                  "version": "12.8.1-021"
                },
                {
                  "status": "affected",
                  "version": "13.8.1-108"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-224"
                },
                {
                  "status": "affected",
                  "version": "14.3.0-120"
                },
                {
                  "status": "affected",
                  "version": "15.0.0-334"
                },
                {
                  "status": "affected",
                  "version": "15.5.1-024"
                },
                {
                  "status": "affected",
                  "version": "15.5.1-029"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "Cisco Secure Web Appliance",
              "vendor": "Cisco",
              "versions": [
                {
                  "status": "affected",
                  "version": "11.8.0-453"
                },
                {
                  "status": "affected",
                  "version": "12.5.3-002"
                },
                {
                  "status": "affected",
                  "version": "12.0.3-007"
                },
                {
                  "status": "affected",
                  "version": "12.0.3-005"
                },
                {
                  "status": "affected",
                  "version": "14.1.0-032"
                },
                {
                  "status": "affected",
                  "version": "14.1.0-047"
                },
                {
                  "status": "affected",
                  "version": "14.1.0-041"
                },
                {
                  "status": "affected",
                  "version": "12.0.4-002"
                },
                {
                  "status": "affected",
                  "version": "14.0.2-012"
                },
                {
                  "status": "affected",
                  "version": "11.8.0-414"
                },
                {
                  "status": "affected",
                  "version": "12.0.1-268"
                },
                {
                  "status": "affected",
                  "version": "11.8.1-023"
                },
                {
                  "status": "affected",
                  "version": "11.8.3-021"
                },
                {
                  "status": "affected",
                  "version": "11.8.3-018"
                },
                {
                  "status": "affected",
                  "version": "12.5.1-011"
                },
                {
                  "status": "affected",
                  "version": "11.8.4-004"
                },
                {
                  "status": "affected",
                  "version": "12.5.2-007"
                },
                {
                  "status": "affected",
                  "version": "12.5.2-011"
                },
                {
                  "status": "affected",
                  "version": "14.5.0-498"
                },
                {
                  "status": "affected",
                  "version": "12.5.4-005"
                },
                {
                  "status": "affected",
                  "version": "12.5.4-011"
                },
                {
                  "status": "affected",
                  "version": "12.0.5-011"
                },
                {
                  "status": "affected",
                  "version": "14.0.3-014"
                },
                {
                  "status": "affected",
                  "version": "12.5.5-004"
                },
                {
                  "status": "affected",
                  "version": "12.5.5-005"
                },
                {
                  "status": "affected",
                  "version": "12.5.5-008"
                },
                {
                  "status": "affected",
                  "version": "14.0.4-005"
                },
                {
                  "status": "affected",
                  "version": "14.5.1-008"
                },
                {
                  "status": "affected",
                  "version": "14.5.1-016"
                },
                {
                  "status": "affected",
                  "version": "15.0.0-355"
                },
                {
                  "status": "affected",
                  "version": "15.0.0-322"
                },
                {
                  "status": "affected",
                  "version": "12.5.6-008"
                },
                {
                  "status": "affected",
                  "version": "15.1.0-287"
                },
                {
                  "status": "affected",
                  "version": "14.5.2-011"
                },
                {
                  "status": "affected",
                  "version": "15.2.0-116"
                },
                {
                  "status": "affected",
                  "version": "14.0.5-007"
                },
                {
                  "status": "affected",
                  "version": "15.2.0-164"
                },
                {
                  "status": "affected",
                  "version": "14.5.1-510"
                },
                {
                  "status": "affected",
                  "version": "12.0.2-012"
                },
                {
                  "status": "affected",
                  "version": "12.0.2-004"
                },
                {
                  "status": "affected",
                  "version": "14.5.1-607"
                },
                {
                  "status": "affected",
                  "version": "14.5.3-033"
                },
                {
                  "status": "affected",
                  "version": "12.0.1-334"
                },
                {
                  "status": "affected",
                  "version": "14.0.1-503"
                },
                {
                  "status": "affected",
                  "version": "14.0.1-053"
                },
                {
                  "status": "affected",
                  "version": "11.8.0-429"
                },
                {
                  "status": "affected",
                  "version": "14.0.1-040"
                },
                {
                  "status": "affected",
                  "version": "14.0.1-014"
                },
                {
                  "status": "affected",
                  "version": "12.5.1-043"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability in Simple Network Management Protocol (SNMP) polling for Cisco Secure Email and Web Manager, Cisco Secure Email Gateway, and Cisco Secure Web Appliance could allow an authenticated, remote attacker to obtain confidential information about the underlying operating system.\r\n\r\nThis vulnerability exists because the appliances do not protect confidential information at rest in response to SNMP poll requests. An attacker could exploit this vulnerability by sending a crafted SNMP poll request to the affected appliance. A successful exploit could allow the attacker to discover confidential information that should be restricted. To exploit this vulnerability, an attacker must have the configured SNMP credentials."
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "value": "The Cisco PSIRT is not aware of any public announcements or malicious use of the vulnerability that is described in this advisory."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
                "version": "3.1"
              },
              "format": "cvssV3_1"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-200",
                  "description": "Exposure of Sensitive Information to an Unauthorized Actor",
                  "lang": "en",
                  "type": "cwe"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-02-05T16:15:06.012Z",
            "orgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
            "shortName": "cisco"
          },
          "references": [
            {
              "name": "cisco-sa-esa-sma-wsa-snmp-inf-FqPvL8sX",
              "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-sma-wsa-snmp-inf-FqPvL8sX"
            }
          ],
          "source": {
            "advisory": "cisco-sa-esa-sma-wsa-snmp-inf-FqPvL8sX",
            "defects": [
              "CSCwk60819"
            ],
            "discovery": "INTERNAL"
          },
          "title": "Cisco Secure Email Gateway, Cisco Secure Email and Web Appliance and Cisco Secure Web Appliance SNMP Polling Information Disclosure Vulnerability"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
        "assignerShortName": "cisco",
        "cveId": "CVE-2025-20207",
        "datePublished": "2025-02-05T16:15:06.012Z",
        "dateReserved": "2024-10-10T19:15:13.230Z",
        "dateUpdated": "2025-02-05T16:57:53.809Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2025-20185 (GCVE-0-2025-20185)

    Vulnerability from nvd – Published: 2025-02-05 16:14 – Updated: 2025-02-05 16:59
    VLAI
    Title
    Cisco Secure Email and Web Manager, Secure Email Gateway, and Secure Web Appliance Privilege Escalation Vulnerability
    Summary
    A vulnerability in the implementation of the remote access functionality of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, Cisco Secure Email Gateway, and Cisco Secure Web Appliance could allow an authenticated, local attacker to elevate privileges to root. The attacker must authenticate with valid administrator credentials. This vulnerability is due to an architectural flaw in the password generation algorithm for the remote access functionality. An attacker could exploit this vulnerability by generating a temporary password for the service account. A successful exploit could allow the attacker to execute arbitrary commands as root and access the underlying operating system. Note: The Security Impact Rating (SIR) for this vulnerability is Medium due to the unrestricted scope of information that is accessible to an attacker.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-02-05 16:59 UTC
    CWE
    • CWE-250 - Execution with Unnecessary Privileges
    Impacted products
    Vendor Product Version
    Cisco Cisco Secure Email Affected: 14.0.0-698
    Affected: 13.5.1-277
    Affected: 13.0.0-392
    Affected: 14.2.0-620
    Affected: 13.0.5-007
    Affected: 13.5.4-038
    Affected: 14.2.1-020
    Affected: 14.3.0-032
    Affected: 15.0.0-104
    Affected: 15.0.1-030
    Affected: 15.5.0-048
    Affected: 15.5.1-055
    Affected: 15.5.2-018
    Affected: 15.0.3-002
    Create a notification for this product.
    Cisco Cisco Secure Email and Web Manager Affected: 13.6.2-023
    Affected: 13.6.2-078
    Affected: 13.0.0-249
    Affected: 13.0.0-277
    Affected: 13.8.1-052
    Affected: 13.8.1-068
    Affected: 13.8.1-074
    Affected: 14.0.0-404
    Affected: 12.8.1-002
    Affected: 14.1.0-227
    Affected: 13.6.1-201
    Affected: 14.2.0-203
    Affected: 14.2.0-212
    Affected: 12.8.1-021
    Affected: 13.8.1-108
    Affected: 14.2.0-224
    Affected: 14.3.0-120
    Affected: 15.0.0-334
    Affected: 15.5.1-024
    Affected: 15.5.1-029
    Affected: 15.5.2-005
    Create a notification for this product.
    Cisco Cisco Secure Web Appliance Affected: 11.8.0-453
    Affected: 12.5.3-002
    Affected: 12.0.3-007
    Affected: 12.0.3-005
    Affected: 14.1.0-032
    Affected: 14.1.0-047
    Affected: 14.1.0-041
    Affected: 12.0.4-002
    Affected: 14.0.2-012
    Affected: 11.8.0-414
    Affected: 12.0.1-268
    Affected: 11.8.1-023
    Affected: 11.8.3-021
    Affected: 11.8.3-018
    Affected: 12.5.1-011
    Affected: 11.8.4-004
    Affected: 12.5.2-007
    Affected: 12.5.2-011
    Affected: 14.5.0-498
    Affected: 12.5.4-005
    Affected: 12.5.4-011
    Affected: 12.0.5-011
    Affected: 14.0.3-014
    Affected: 12.5.5-004
    Affected: 12.5.5-005
    Affected: 12.5.5-008
    Affected: 14.0.4-005
    Affected: 14.5.1-008
    Affected: 14.5.1-016
    Affected: 15.0.0-355
    Affected: 15.0.0-322
    Affected: 12.5.6-008
    Affected: 15.1.0-287
    Affected: 14.5.2-011
    Affected: 15.2.0-116
    Affected: 14.0.5-007
    Affected: 15.2.0-164
    Affected: 14.5.1-510
    Affected: 12.0.2-012
    Affected: 12.0.2-004
    Affected: 14.5.1-607
    Affected: 14.5.3-033
    Affected: 15.0.1-004
    Affected: 15.2.1-011
    Affected: 14.5.0-673
    Affected: 14.5.0-537
    Affected: 12.0.1-334
    Affected: 14.0.1-503
    Affected: 14.0.1-053
    Affected: 11.8.0-429
    Affected: 14.0.1-040
    Affected: 14.0.1-014
    Affected: 12.5.1-043
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-20185",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-02-05T16:59:20.922545Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-02-05T16:59:47.445Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "Cisco Secure Email",
              "vendor": "Cisco",
              "versions": [
                {
                  "status": "affected",
                  "version": "14.0.0-698"
                },
                {
                  "status": "affected",
                  "version": "13.5.1-277"
                },
                {
                  "status": "affected",
                  "version": "13.0.0-392"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-620"
                },
                {
                  "status": "affected",
                  "version": "13.0.5-007"
                },
                {
                  "status": "affected",
                  "version": "13.5.4-038"
                },
                {
                  "status": "affected",
                  "version": "14.2.1-020"
                },
                {
                  "status": "affected",
                  "version": "14.3.0-032"
                },
                {
                  "status": "affected",
                  "version": "15.0.0-104"
                },
                {
                  "status": "affected",
                  "version": "15.0.1-030"
                },
                {
                  "status": "affected",
                  "version": "15.5.0-048"
                },
                {
                  "status": "affected",
                  "version": "15.5.1-055"
                },
                {
                  "status": "affected",
                  "version": "15.5.2-018"
                },
                {
                  "status": "affected",
                  "version": "15.0.3-002"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "Cisco Secure Email and Web Manager",
              "vendor": "Cisco",
              "versions": [
                {
                  "status": "affected",
                  "version": "13.6.2-023"
                },
                {
                  "status": "affected",
                  "version": "13.6.2-078"
                },
                {
                  "status": "affected",
                  "version": "13.0.0-249"
                },
                {
                  "status": "affected",
                  "version": "13.0.0-277"
                },
                {
                  "status": "affected",
                  "version": "13.8.1-052"
                },
                {
                  "status": "affected",
                  "version": "13.8.1-068"
                },
                {
                  "status": "affected",
                  "version": "13.8.1-074"
                },
                {
                  "status": "affected",
                  "version": "14.0.0-404"
                },
                {
                  "status": "affected",
                  "version": "12.8.1-002"
                },
                {
                  "status": "affected",
                  "version": "14.1.0-227"
                },
                {
                  "status": "affected",
                  "version": "13.6.1-201"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-203"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-212"
                },
                {
                  "status": "affected",
                  "version": "12.8.1-021"
                },
                {
                  "status": "affected",
                  "version": "13.8.1-108"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-224"
                },
                {
                  "status": "affected",
                  "version": "14.3.0-120"
                },
                {
                  "status": "affected",
                  "version": "15.0.0-334"
                },
                {
                  "status": "affected",
                  "version": "15.5.1-024"
                },
                {
                  "status": "affected",
                  "version": "15.5.1-029"
                },
                {
                  "status": "affected",
                  "version": "15.5.2-005"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "Cisco Secure Web Appliance",
              "vendor": "Cisco",
              "versions": [
                {
                  "status": "affected",
                  "version": "11.8.0-453"
                },
                {
                  "status": "affected",
                  "version": "12.5.3-002"
                },
                {
                  "status": "affected",
                  "version": "12.0.3-007"
                },
                {
                  "status": "affected",
                  "version": "12.0.3-005"
                },
                {
                  "status": "affected",
                  "version": "14.1.0-032"
                },
                {
                  "status": "affected",
                  "version": "14.1.0-047"
                },
                {
                  "status": "affected",
                  "version": "14.1.0-041"
                },
                {
                  "status": "affected",
                  "version": "12.0.4-002"
                },
                {
                  "status": "affected",
                  "version": "14.0.2-012"
                },
                {
                  "status": "affected",
                  "version": "11.8.0-414"
                },
                {
                  "status": "affected",
                  "version": "12.0.1-268"
                },
                {
                  "status": "affected",
                  "version": "11.8.1-023"
                },
                {
                  "status": "affected",
                  "version": "11.8.3-021"
                },
                {
                  "status": "affected",
                  "version": "11.8.3-018"
                },
                {
                  "status": "affected",
                  "version": "12.5.1-011"
                },
                {
                  "status": "affected",
                  "version": "11.8.4-004"
                },
                {
                  "status": "affected",
                  "version": "12.5.2-007"
                },
                {
                  "status": "affected",
                  "version": "12.5.2-011"
                },
                {
                  "status": "affected",
                  "version": "14.5.0-498"
                },
                {
                  "status": "affected",
                  "version": "12.5.4-005"
                },
                {
                  "status": "affected",
                  "version": "12.5.4-011"
                },
                {
                  "status": "affected",
                  "version": "12.0.5-011"
                },
                {
                  "status": "affected",
                  "version": "14.0.3-014"
                },
                {
                  "status": "affected",
                  "version": "12.5.5-004"
                },
                {
                  "status": "affected",
                  "version": "12.5.5-005"
                },
                {
                  "status": "affected",
                  "version": "12.5.5-008"
                },
                {
                  "status": "affected",
                  "version": "14.0.4-005"
                },
                {
                  "status": "affected",
                  "version": "14.5.1-008"
                },
                {
                  "status": "affected",
                  "version": "14.5.1-016"
                },
                {
                  "status": "affected",
                  "version": "15.0.0-355"
                },
                {
                  "status": "affected",
                  "version": "15.0.0-322"
                },
                {
                  "status": "affected",
                  "version": "12.5.6-008"
                },
                {
                  "status": "affected",
                  "version": "15.1.0-287"
                },
                {
                  "status": "affected",
                  "version": "14.5.2-011"
                },
                {
                  "status": "affected",
                  "version": "15.2.0-116"
                },
                {
                  "status": "affected",
                  "version": "14.0.5-007"
                },
                {
                  "status": "affected",
                  "version": "15.2.0-164"
                },
                {
                  "status": "affected",
                  "version": "14.5.1-510"
                },
                {
                  "status": "affected",
                  "version": "12.0.2-012"
                },
                {
                  "status": "affected",
                  "version": "12.0.2-004"
                },
                {
                  "status": "affected",
                  "version": "14.5.1-607"
                },
                {
                  "status": "affected",
                  "version": "14.5.3-033"
                },
                {
                  "status": "affected",
                  "version": "15.0.1-004"
                },
                {
                  "status": "affected",
                  "version": "15.2.1-011"
                },
                {
                  "status": "affected",
                  "version": "14.5.0-673"
                },
                {
                  "status": "affected",
                  "version": "14.5.0-537"
                },
                {
                  "status": "affected",
                  "version": "12.0.1-334"
                },
                {
                  "status": "affected",
                  "version": "14.0.1-503"
                },
                {
                  "status": "affected",
                  "version": "14.0.1-053"
                },
                {
                  "status": "affected",
                  "version": "11.8.0-429"
                },
                {
                  "status": "affected",
                  "version": "14.0.1-040"
                },
                {
                  "status": "affected",
                  "version": "14.0.1-014"
                },
                {
                  "status": "affected",
                  "version": "12.5.1-043"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability in the implementation of the remote access functionality of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, Cisco Secure Email Gateway, and Cisco Secure Web Appliance could allow an authenticated, local attacker to elevate privileges to root. The attacker must authenticate with valid administrator credentials.\r\n\r\nThis vulnerability is due to an architectural flaw in the password generation algorithm for the remote access functionality. An attacker could exploit this vulnerability by generating a temporary password for the service account. A successful exploit could allow the attacker to execute arbitrary commands as root and access the underlying operating system.\r\nNote: The Security Impact Rating (SIR) for this vulnerability is Medium due to the unrestricted scope of information that is accessible to an attacker."
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "value": "The Cisco PSIRT is not aware of any public announcements or malicious use of the vulnerabilities that are described in this advisory."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "NONE",
                "baseScore": 3.4,
                "baseSeverity": "LOW",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N",
                "version": "3.1"
              },
              "format": "cvssV3_1"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-250",
                  "description": "Execution with Unnecessary Privileges",
                  "lang": "en",
                  "type": "cwe"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-02-05T16:14:38.541Z",
            "orgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
            "shortName": "cisco"
          },
          "references": [
            {
              "name": "cisco-sa-esa-sma-wsa-multi-yKUJhS34",
              "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-sma-wsa-multi-yKUJhS34"
            }
          ],
          "source": {
            "advisory": "cisco-sa-esa-sma-wsa-multi-yKUJhS34",
            "defects": [
              "CSCwk70576"
            ],
            "discovery": "EXTERNAL"
          },
          "title": "Cisco Secure Email and Web Manager, Secure Email Gateway, and Secure Web Appliance Privilege Escalation Vulnerability"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
        "assignerShortName": "cisco",
        "cveId": "CVE-2025-20185",
        "datePublished": "2025-02-05T16:14:38.541Z",
        "dateReserved": "2024-10-10T19:15:13.226Z",
        "dateUpdated": "2025-02-05T16:59:47.445Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2025-20184 (GCVE-0-2025-20184)

    Vulnerability from nvd – Published: 2025-02-05 16:14 – Updated: 2025-02-05 17:00
    VLAI
    Title
    Cisco Secure Email and Web Manager and Secure Web Appliance Command Injection Vulnerability
    Summary
    A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Web Appliance could allow an authenticated, remote attacker to perform command injection attacks against an affected device. The attacker must authenticate with valid administrator credentials. This vulnerability is due to insufficient validation of XML configuration files by an affected device. An attacker could exploit this vulnerability by uploading a crafted XML configuration file. A successful exploit could allow the attacker to inject commands to the underlying operating system with root privileges.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-02-05 16:59 UTC
    CWE
    • CWE-20 - Improper Input Validation
    Impacted products
    Vendor Product Version
    Cisco Cisco Secure Email Affected: 14.0.0-698
    Affected: 13.5.1-277
    Affected: 13.0.0-392
    Affected: 14.2.0-620
    Affected: 13.0.5-007
    Affected: 13.5.4-038
    Affected: 14.2.1-020
    Affected: 14.3.0-032
    Affected: 15.0.0-104
    Affected: 15.0.1-030
    Affected: 15.5.0-048
    Affected: 15.5.1-055
    Affected: 15.5.2-018
    Affected: 15.0.3-002
    Affected: 15.5.3-022
    Create a notification for this product.
    Cisco Cisco Secure Web Appliance Affected: 11.8.0-453
    Affected: 12.5.3-002
    Affected: 12.0.3-007
    Affected: 12.0.3-005
    Affected: 14.1.0-032
    Affected: 14.1.0-047
    Affected: 14.1.0-041
    Affected: 12.0.4-002
    Affected: 14.0.2-012
    Affected: 11.8.0-414
    Affected: 12.0.1-268
    Affected: 11.8.1-023
    Affected: 11.8.3-021
    Affected: 11.8.3-018
    Affected: 12.5.1-011
    Affected: 11.8.4-004
    Affected: 12.5.2-007
    Affected: 12.5.2-011
    Affected: 14.5.0-498
    Affected: 12.5.4-005
    Affected: 12.5.4-011
    Affected: 12.0.5-011
    Affected: 14.0.3-014
    Affected: 12.5.5-004
    Affected: 12.5.5-005
    Affected: 12.5.5-008
    Affected: 14.0.4-005
    Affected: 14.5.1-008
    Affected: 14.5.1-016
    Affected: 15.0.0-355
    Affected: 15.0.0-322
    Affected: 12.5.6-008
    Affected: 15.1.0-287
    Affected: 14.5.2-011
    Affected: 15.2.0-116
    Affected: 14.0.5-007
    Affected: 15.2.0-164
    Affected: 14.5.1-510
    Affected: 12.0.2-012
    Affected: 12.0.2-004
    Affected: 14.5.1-607
    Affected: 14.5.3-033
    Affected: 15.0.1-004
    Affected: 15.2.1-011
    Affected: 14.5.0-673
    Affected: 14.5.0-537
    Affected: 12.0.1-334
    Affected: 14.0.1-503
    Affected: 14.0.1-053
    Affected: 11.8.0-429
    Affected: 14.0.1-040
    Affected: 14.0.1-014
    Affected: 12.5.1-043
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-20184",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-02-05T16:59:57.945223Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-02-05T17:00:15.021Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "Cisco Secure Email",
              "vendor": "Cisco",
              "versions": [
                {
                  "status": "affected",
                  "version": "14.0.0-698"
                },
                {
                  "status": "affected",
                  "version": "13.5.1-277"
                },
                {
                  "status": "affected",
                  "version": "13.0.0-392"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-620"
                },
                {
                  "status": "affected",
                  "version": "13.0.5-007"
                },
                {
                  "status": "affected",
                  "version": "13.5.4-038"
                },
                {
                  "status": "affected",
                  "version": "14.2.1-020"
                },
                {
                  "status": "affected",
                  "version": "14.3.0-032"
                },
                {
                  "status": "affected",
                  "version": "15.0.0-104"
                },
                {
                  "status": "affected",
                  "version": "15.0.1-030"
                },
                {
                  "status": "affected",
                  "version": "15.5.0-048"
                },
                {
                  "status": "affected",
                  "version": "15.5.1-055"
                },
                {
                  "status": "affected",
                  "version": "15.5.2-018"
                },
                {
                  "status": "affected",
                  "version": "15.0.3-002"
                },
                {
                  "status": "affected",
                  "version": "15.5.3-022"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "Cisco Secure Web Appliance",
              "vendor": "Cisco",
              "versions": [
                {
                  "status": "affected",
                  "version": "11.8.0-453"
                },
                {
                  "status": "affected",
                  "version": "12.5.3-002"
                },
                {
                  "status": "affected",
                  "version": "12.0.3-007"
                },
                {
                  "status": "affected",
                  "version": "12.0.3-005"
                },
                {
                  "status": "affected",
                  "version": "14.1.0-032"
                },
                {
                  "status": "affected",
                  "version": "14.1.0-047"
                },
                {
                  "status": "affected",
                  "version": "14.1.0-041"
                },
                {
                  "status": "affected",
                  "version": "12.0.4-002"
                },
                {
                  "status": "affected",
                  "version": "14.0.2-012"
                },
                {
                  "status": "affected",
                  "version": "11.8.0-414"
                },
                {
                  "status": "affected",
                  "version": "12.0.1-268"
                },
                {
                  "status": "affected",
                  "version": "11.8.1-023"
                },
                {
                  "status": "affected",
                  "version": "11.8.3-021"
                },
                {
                  "status": "affected",
                  "version": "11.8.3-018"
                },
                {
                  "status": "affected",
                  "version": "12.5.1-011"
                },
                {
                  "status": "affected",
                  "version": "11.8.4-004"
                },
                {
                  "status": "affected",
                  "version": "12.5.2-007"
                },
                {
                  "status": "affected",
                  "version": "12.5.2-011"
                },
                {
                  "status": "affected",
                  "version": "14.5.0-498"
                },
                {
                  "status": "affected",
                  "version": "12.5.4-005"
                },
                {
                  "status": "affected",
                  "version": "12.5.4-011"
                },
                {
                  "status": "affected",
                  "version": "12.0.5-011"
                },
                {
                  "status": "affected",
                  "version": "14.0.3-014"
                },
                {
                  "status": "affected",
                  "version": "12.5.5-004"
                },
                {
                  "status": "affected",
                  "version": "12.5.5-005"
                },
                {
                  "status": "affected",
                  "version": "12.5.5-008"
                },
                {
                  "status": "affected",
                  "version": "14.0.4-005"
                },
                {
                  "status": "affected",
                  "version": "14.5.1-008"
                },
                {
                  "status": "affected",
                  "version": "14.5.1-016"
                },
                {
                  "status": "affected",
                  "version": "15.0.0-355"
                },
                {
                  "status": "affected",
                  "version": "15.0.0-322"
                },
                {
                  "status": "affected",
                  "version": "12.5.6-008"
                },
                {
                  "status": "affected",
                  "version": "15.1.0-287"
                },
                {
                  "status": "affected",
                  "version": "14.5.2-011"
                },
                {
                  "status": "affected",
                  "version": "15.2.0-116"
                },
                {
                  "status": "affected",
                  "version": "14.0.5-007"
                },
                {
                  "status": "affected",
                  "version": "15.2.0-164"
                },
                {
                  "status": "affected",
                  "version": "14.5.1-510"
                },
                {
                  "status": "affected",
                  "version": "12.0.2-012"
                },
                {
                  "status": "affected",
                  "version": "12.0.2-004"
                },
                {
                  "status": "affected",
                  "version": "14.5.1-607"
                },
                {
                  "status": "affected",
                  "version": "14.5.3-033"
                },
                {
                  "status": "affected",
                  "version": "15.0.1-004"
                },
                {
                  "status": "affected",
                  "version": "15.2.1-011"
                },
                {
                  "status": "affected",
                  "version": "14.5.0-673"
                },
                {
                  "status": "affected",
                  "version": "14.5.0-537"
                },
                {
                  "status": "affected",
                  "version": "12.0.1-334"
                },
                {
                  "status": "affected",
                  "version": "14.0.1-503"
                },
                {
                  "status": "affected",
                  "version": "14.0.1-053"
                },
                {
                  "status": "affected",
                  "version": "11.8.0-429"
                },
                {
                  "status": "affected",
                  "version": "14.0.1-040"
                },
                {
                  "status": "affected",
                  "version": "14.0.1-014"
                },
                {
                  "status": "affected",
                  "version": "12.5.1-043"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Web Appliance could allow an authenticated, remote attacker to perform command injection attacks against an affected device. The attacker must authenticate with valid administrator credentials.\r\n\r\nThis vulnerability is due to insufficient validation of XML configuration files by an affected device. An attacker could exploit this vulnerability by uploading a crafted XML configuration file. A successful exploit could allow the attacker to inject commands to the underlying operating system with root privileges."
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "value": "The Cisco PSIRT is not aware of any public announcements or malicious use of the vulnerabilities that are described in this advisory."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N",
                "version": "3.1"
              },
              "format": "cvssV3_1"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-20",
                  "description": "Improper Input Validation",
                  "lang": "en",
                  "type": "cwe"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-02-05T16:14:30.863Z",
            "orgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
            "shortName": "cisco"
          },
          "references": [
            {
              "name": "cisco-sa-esa-sma-wsa-multi-yKUJhS34",
              "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-sma-wsa-multi-yKUJhS34"
            }
          ],
          "source": {
            "advisory": "cisco-sa-esa-sma-wsa-multi-yKUJhS34",
            "defects": [
              "CSCwk70559"
            ],
            "discovery": "EXTERNAL"
          },
          "title": "Cisco Secure Email and Web Manager and Secure Web Appliance Command Injection Vulnerability"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
        "assignerShortName": "cisco",
        "cveId": "CVE-2025-20184",
        "datePublished": "2025-02-05T16:14:30.863Z",
        "dateReserved": "2024-10-10T19:15:13.225Z",
        "dateUpdated": "2025-02-05T17:00:15.021Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2025-20180 (GCVE-0-2025-20180)

    Vulnerability from nvd – Published: 2025-02-05 16:14 – Updated: 2025-02-05 17:20
    VLAI
    Title
    Cisco Secure Email and Web Manager and Secure Email Gateway Cross-Site Scripting Vulnerability
    Summary
    A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Email Gateway could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker must have valid credentials for a user account with at least the role of Operator.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-02-05 17:20 UTC
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    Impacted products
    Vendor Product Version
    Cisco Cisco Secure Email Affected: 14.0.0-698
    Affected: 13.5.1-277
    Affected: 13.0.0-392
    Affected: 14.2.0-620
    Affected: 13.0.5-007
    Affected: 13.5.4-038
    Affected: 14.2.1-020
    Affected: 14.3.0-032
    Affected: 15.0.0-104
    Affected: 15.0.1-030
    Affected: 15.5.0-048
    Affected: 15.5.1-055
    Affected: 15.5.2-018
    Affected: 16.0.0-050
    Affected: 15.0.3-002
    Affected: 16.0.0-054
    Create a notification for this product.
    Cisco Cisco Secure Email and Web Manager Affected: 13.6.2-023
    Affected: 13.6.2-078
    Affected: 13.0.0-249
    Affected: 13.0.0-277
    Affected: 13.8.1-052
    Affected: 13.8.1-068
    Affected: 13.8.1-074
    Affected: 14.0.0-404
    Affected: 12.8.1-002
    Affected: 14.1.0-227
    Affected: 13.6.1-201
    Affected: 14.2.0-203
    Affected: 14.2.0-212
    Affected: 12.8.1-021
    Affected: 13.8.1-108
    Affected: 14.2.0-224
    Affected: 14.3.0-120
    Affected: 15.0.0-334
    Affected: 15.5.1-024
    Affected: 15.5.1-029
    Affected: 15.5.2-005
    Affected: 16.0.0-195
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-20180",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-02-05T17:20:31.169165Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-02-05T17:20:45.616Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "Cisco Secure Email",
              "vendor": "Cisco",
              "versions": [
                {
                  "status": "affected",
                  "version": "14.0.0-698"
                },
                {
                  "status": "affected",
                  "version": "13.5.1-277"
                },
                {
                  "status": "affected",
                  "version": "13.0.0-392"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-620"
                },
                {
                  "status": "affected",
                  "version": "13.0.5-007"
                },
                {
                  "status": "affected",
                  "version": "13.5.4-038"
                },
                {
                  "status": "affected",
                  "version": "14.2.1-020"
                },
                {
                  "status": "affected",
                  "version": "14.3.0-032"
                },
                {
                  "status": "affected",
                  "version": "15.0.0-104"
                },
                {
                  "status": "affected",
                  "version": "15.0.1-030"
                },
                {
                  "status": "affected",
                  "version": "15.5.0-048"
                },
                {
                  "status": "affected",
                  "version": "15.5.1-055"
                },
                {
                  "status": "affected",
                  "version": "15.5.2-018"
                },
                {
                  "status": "affected",
                  "version": "16.0.0-050"
                },
                {
                  "status": "affected",
                  "version": "15.0.3-002"
                },
                {
                  "status": "affected",
                  "version": "16.0.0-054"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "Cisco Secure Email and Web Manager",
              "vendor": "Cisco",
              "versions": [
                {
                  "status": "affected",
                  "version": "13.6.2-023"
                },
                {
                  "status": "affected",
                  "version": "13.6.2-078"
                },
                {
                  "status": "affected",
                  "version": "13.0.0-249"
                },
                {
                  "status": "affected",
                  "version": "13.0.0-277"
                },
                {
                  "status": "affected",
                  "version": "13.8.1-052"
                },
                {
                  "status": "affected",
                  "version": "13.8.1-068"
                },
                {
                  "status": "affected",
                  "version": "13.8.1-074"
                },
                {
                  "status": "affected",
                  "version": "14.0.0-404"
                },
                {
                  "status": "affected",
                  "version": "12.8.1-002"
                },
                {
                  "status": "affected",
                  "version": "14.1.0-227"
                },
                {
                  "status": "affected",
                  "version": "13.6.1-201"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-203"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-212"
                },
                {
                  "status": "affected",
                  "version": "12.8.1-021"
                },
                {
                  "status": "affected",
                  "version": "13.8.1-108"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-224"
                },
                {
                  "status": "affected",
                  "version": "14.3.0-120"
                },
                {
                  "status": "affected",
                  "version": "15.0.0-334"
                },
                {
                  "status": "affected",
                  "version": "15.5.1-024"
                },
                {
                  "status": "affected",
                  "version": "15.5.1-029"
                },
                {
                  "status": "affected",
                  "version": "15.5.2-005"
                },
                {
                  "status": "affected",
                  "version": "16.0.0-195"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Email Gateway could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface.\r\n\r\nThis vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker must have valid credentials for a user account with at least the role of Operator."
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "value": "The Cisco PSIRT is not aware of any public announcements or malicious use of the vulnerability that is described in this advisory."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 4.8,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "HIGH",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N",
                "version": "3.1"
              },
              "format": "cvssV3_1"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "cwe"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-02-05T16:14:11.746Z",
            "orgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
            "shortName": "cisco"
          },
          "references": [
            {
              "name": "cisco-sa-esa-sma-xss-WCk2WcuG",
              "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-sma-xss-WCk2WcuG"
            }
          ],
          "source": {
            "advisory": "cisco-sa-esa-sma-xss-WCk2WcuG",
            "defects": [
              "CSCwn25954"
            ],
            "discovery": "INTERNAL"
          },
          "title": "Cisco Secure Email and Web Manager and Secure Email Gateway Cross-Site Scripting Vulnerability"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
        "assignerShortName": "cisco",
        "cveId": "CVE-2025-20180",
        "datePublished": "2025-02-05T16:14:11.746Z",
        "dateReserved": "2024-10-10T19:15:13.225Z",
        "dateUpdated": "2025-02-05T17:20:45.616Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2020-3548 (GCVE-0-2020-3548)

    Vulnerability from nvd – Published: 2024-11-18 15:53 – Updated: 2024-11-18 16:32
    VLAI
    Title
    Cisco Email Security Appliance Denial Of Service Vulnerability
    Summary
    A vulnerability in the Transport Layer Security (TLS) protocol implementation of Cisco AsyncOS software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause high CPU usage on an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to inefficient processing of incoming TLS traffic. An attacker could exploit this vulnerability by sending a series of crafted TLS packets to an affected device. A successful exploit could allow the attacker to trigger a prolonged state of high CPU utilization. The affected device would still be operative, but response time and overall performance may be degraded.There are no workarounds that address this vulnerability.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-11-18 16:30 UTC
    CWE
    • CWE-407 - Inefficient Algorithmic Complexity
    Impacted products
    Vendor Product Version
    Cisco Cisco Secure Email Affected: N/A
    Create a notification for this product.
    cisco secure_email Affected: 0 , ≤ 13.5.1-277 (custom)
        cpe:2.3:a:cisco:secure_email:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:cisco:secure_email:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "secure_email",
                "vendor": "cisco",
                "versions": [
                  {
                    "lessThanOrEqual": "13.5.1-277",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2020-3548",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-11-18T16:30:29.514984Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-11-18T16:32:04.999Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Cisco Secure Email",
              "vendor": "Cisco",
              "versions": [
                {
                  "status": "affected",
                  "version": "N/A"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability in the Transport Layer Security (TLS) protocol implementation of Cisco\u0026nbsp;AsyncOS software for Cisco\u0026nbsp;Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause high CPU usage on an affected device, resulting in a denial of service (DoS) condition.\r\nThe vulnerability is due to inefficient processing of incoming TLS traffic. An attacker could exploit this vulnerability by sending a series of crafted TLS packets to an affected device. A successful exploit could allow the attacker to trigger a prolonged state of high CPU utilization. The affected device would still be operative, but response time and overall performance may be degraded.There are no workarounds that address this vulnerability."
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "value": "The Cisco Product Security Incident Response Team (PSIRT) is not aware of any public announcements or malicious use of the vulnerability that is described in this advisory."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/RL:X/RC:X/E:X",
                "version": "3.1"
              },
              "format": "cvssV3_1"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-407",
                  "description": "Inefficient Algorithmic Complexity",
                  "lang": "en",
                  "type": "cwe"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-11-18T15:53:40.744Z",
            "orgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
            "shortName": "cisco"
          },
          "references": [
            {
              "name": "cisco-sa-esa-tls-dos-xW53TBhb",
              "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-tls-dos-xW53TBhb"
            }
          ],
          "source": {
            "advisory": "cisco-sa-esa-tls-dos-xW53TBhb",
            "defects": [
              "CSCvu35999"
            ],
            "discovery": "INTERNAL"
          },
          "title": "Cisco Email Security Appliance Denial Of Service Vulnerability"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
        "assignerShortName": "cisco",
        "cveId": "CVE-2020-3548",
        "datePublished": "2024-11-18T15:53:40.744Z",
        "dateReserved": "2019-12-12T00:00:00.000Z",
        "dateUpdated": "2024-11-18T16:32:04.999Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-20504 (GCVE-0-2024-20504)

    Vulnerability from nvd – Published: 2024-11-06 16:29 – Updated: 2024-11-06 17:05
    VLAI
    Title
    Cisco Secure Email and Web Manager, Secure Email Gateway, and Secure Web Appliance Stored Cross-Site Scripting Vulnerabilities
    Summary
    A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, Secure Email Gateway, and Secure Web Appliance could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-11-06 17:05 UTC
    CWE
    • CWE-80 - Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
    Impacted products
    Vendor Product Version
    Cisco Cisco Secure Email Affected: 14.0.0-698
    Affected: 14.2.0-620
    Affected: 14.2.1-020
    Affected: 14.3.0-032
    Affected: 15.0.0-104
    Affected: 15.0.1-030
    Affected: 15.5.0-048
    Affected: 15.5.1-055
    Create a notification for this product.
    Cisco Cisco Secure Email and Web Manager Affected: 14.0.0-404
    Affected: 14.1.0-223
    Affected: 14.1.0-227
    Affected: 14.2.0-212
    Affected: 14.2.0-224
    Affected: 14.2.1-020
    Affected: 14.3.0-120
    Affected: 15.0.0-334
    Affected: 15.5.1-024
    Affected: 15.5.1-029
    Create a notification for this product.
    Cisco Cisco Secure Web Appliance Affected: 14.1.0-032
    Affected: 14.1.0-047
    Affected: 14.1.0-041
    Affected: 14.0.2-012
    Affected: 14.5.0-498
    Affected: 14.0.3-014
    Affected: 14.0.4-005
    Affected: 14.5.1-008
    Affected: 14.5.1-016
    Affected: 15.0.0-355
    Affected: 15.0.0-322
    Affected: 15.1.0-287
    Affected: 14.5.2-011
    Affected: 15.2.0-116
    Affected: 14.0.5-007
    Affected: 15.2.0-164
    Affected: 14.5.1-510
    Affected: 14.5.1-607
    Affected: 14.5.3-033
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-20504",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-11-06T17:05:32.372312Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-11-06T17:05:40.097Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "Cisco Secure Email",
              "vendor": "Cisco",
              "versions": [
                {
                  "status": "affected",
                  "version": "14.0.0-698"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-620"
                },
                {
                  "status": "affected",
                  "version": "14.2.1-020"
                },
                {
                  "status": "affected",
                  "version": "14.3.0-032"
                },
                {
                  "status": "affected",
                  "version": "15.0.0-104"
                },
                {
                  "status": "affected",
                  "version": "15.0.1-030"
                },
                {
                  "status": "affected",
                  "version": "15.5.0-048"
                },
                {
                  "status": "affected",
                  "version": "15.5.1-055"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "Cisco Secure Email and Web Manager",
              "vendor": "Cisco",
              "versions": [
                {
                  "status": "affected",
                  "version": "14.0.0-404"
                },
                {
                  "status": "affected",
                  "version": "14.1.0-223"
                },
                {
                  "status": "affected",
                  "version": "14.1.0-227"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-212"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-224"
                },
                {
                  "status": "affected",
                  "version": "14.2.1-020"
                },
                {
                  "status": "affected",
                  "version": "14.3.0-120"
                },
                {
                  "status": "affected",
                  "version": "15.0.0-334"
                },
                {
                  "status": "affected",
                  "version": "15.5.1-024"
                },
                {
                  "status": "affected",
                  "version": "15.5.1-029"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "Cisco Secure Web Appliance",
              "vendor": "Cisco",
              "versions": [
                {
                  "status": "affected",
                  "version": "14.1.0-032"
                },
                {
                  "status": "affected",
                  "version": "14.1.0-047"
                },
                {
                  "status": "affected",
                  "version": "14.1.0-041"
                },
                {
                  "status": "affected",
                  "version": "14.0.2-012"
                },
                {
                  "status": "affected",
                  "version": "14.5.0-498"
                },
                {
                  "status": "affected",
                  "version": "14.0.3-014"
                },
                {
                  "status": "affected",
                  "version": "14.0.4-005"
                },
                {
                  "status": "affected",
                  "version": "14.5.1-008"
                },
                {
                  "status": "affected",
                  "version": "14.5.1-016"
                },
                {
                  "status": "affected",
                  "version": "15.0.0-355"
                },
                {
                  "status": "affected",
                  "version": "15.0.0-322"
                },
                {
                  "status": "affected",
                  "version": "15.1.0-287"
                },
                {
                  "status": "affected",
                  "version": "14.5.2-011"
                },
                {
                  "status": "affected",
                  "version": "15.2.0-116"
                },
                {
                  "status": "affected",
                  "version": "14.0.5-007"
                },
                {
                  "status": "affected",
                  "version": "15.2.0-164"
                },
                {
                  "status": "affected",
                  "version": "14.5.1-510"
                },
                {
                  "status": "affected",
                  "version": "14.5.1-607"
                },
                {
                  "status": "affected",
                  "version": "14.5.3-033"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, Secure Email Gateway, and Secure Web Appliance could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface.\r\n\r\nThis vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information."
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "value": "The Cisco PSIRT is not aware of any public announcements or malicious use of the vulnerability that is described in this advisory."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.4,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
                "version": "3.1"
              },
              "format": "cvssV3_1"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-80",
                  "description": "Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)",
                  "lang": "en",
                  "type": "cwe"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-11-06T16:29:37.791Z",
            "orgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
            "shortName": "cisco"
          },
          "references": [
            {
              "name": "cisco-sa-esa-wsa-sma-xss-zYm3f49n",
              "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-wsa-sma-xss-zYm3f49n"
            }
          ],
          "source": {
            "advisory": "cisco-sa-esa-wsa-sma-xss-zYm3f49n",
            "defects": [
              "CSCwj72814"
            ],
            "discovery": "EXTERNAL"
          },
          "title": "Cisco Secure Email and Web Manager, Secure Email Gateway, and Secure Web Appliance Stored Cross-Site Scripting Vulnerabilities"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
        "assignerShortName": "cisco",
        "cveId": "CVE-2024-20504",
        "datePublished": "2024-11-06T16:29:37.791Z",
        "dateReserved": "2023-11-08T15:08:07.687Z",
        "dateUpdated": "2024-11-06T17:05:40.097Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2026-76442 (GCVE-0-2026-76442)

    Vulnerability from cvelistv5 – Published: 2026-09-14 16:09 – Updated: 2026-09-16 03:55
    VLAI
    Title
    Cisco Secure Email Gateway Security Hardening Release
    Summary
    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76442 are related to issues with improper validation of specified quantity in input that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-1284.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-14 00:00 UTC
    CWE
    • CWE-1284 - Improper Validation of Specified Quantity in Input
    Impacted products
    Vendor Product Version
    Cisco Cisco Secure Email Affected: 14.0.0-698
    Affected: 13.5.1-277
    Affected: 13.0.0-392
    Affected: 14.2.0-620
    Affected: 13.0.5-007
    Affected: 13.5.4-038
    Affected: 14.2.1-020
    Affected: 14.3.0-032
    Affected: 15.0.0-104
    Affected: 15.0.1-030
    Affected: 15.5.0-048
    Affected: 15.5.1-055
    Affected: 15.5.2-018
    Affected: 16.0.0-050
    Affected: 15.0.3-002
    Affected: 16.0.0-054
    Affected: 15.5.3-022
    Affected: 16.0.1-017
    Affected: 15.5.4-012
    Affected: 16.0.4-016
    Affected: 15.0.5-016
    Affected: 16.0.2-112
    Affected: 16.0.3-044
    Affected: 16.5.0-780
    Create a notification for this product.
    Cisco Cisco Secure Email and Web Manager Affected: 13.6.2-023
    Affected: 13.6.2-078
    Affected: 13.0.0-249
    Affected: 13.0.0-277
    Affected: 13.8.1-052
    Affected: 13.8.1-068
    Affected: 13.8.1-074
    Affected: 14.0.0-404
    Affected: 12.8.1-002
    Affected: 14.1.0-227
    Affected: 13.6.1-201
    Affected: 14.2.0-203
    Affected: 14.2.0-212
    Affected: 12.8.1-021
    Affected: 13.8.1-108
    Affected: 14.2.0-224
    Affected: 14.3.0-120
    Affected: 15.0.0-334
    Affected: 15.5.1-024
    Affected: 15.5.1-029
    Affected: 15.5.2-005
    Affected: 16.0.0-195
    Affected: 15.5.3-017
    Affected: 16.0.1-010
    Affected: 15.0.1-035
    Affected: 16.0.2-088
    Affected: 15.5.4-007
    Affected: 15.0.2-007
    Affected: 16.0.4-010
    Affected: 16.0.3-016
    Affected: 16.5.0-429
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-76442",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-14T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-16T03:55:36.952Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "descriptions": [
              {
                "lang": "en",
                "value": "The CVE Program recognizes that this CVE Record provides vulnerability information that a Supplier CNA believes is very important to consumers. The CVE Program has flagged this CVE Record as it assigns a single CVE ID to a collection of individual vulnerabilities which does not align with CVE\u0027s \"one vulnerability, one ID\" principle, and therefore provides incomplete information. For further clarification, please see the CVE Program\u0027s blog, \"Preserving Vulnerability-Level Identification\" linked below. Details within the CNA container below are viewable by clicking on the CNA name."
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-15T17:03:58.176Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://www.cve.org/Media/News/item/blog/2026/06/16/Preserving-Vulnerability-Level-Identification"
              }
            ],
            "tags": [
              "x_bundling-flagged-by-CVE-Program"
            ]
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "Cisco Secure Email",
              "vendor": "Cisco",
              "versions": [
                {
                  "status": "affected",
                  "version": "14.0.0-698"
                },
                {
                  "status": "affected",
                  "version": "13.5.1-277"
                },
                {
                  "status": "affected",
                  "version": "13.0.0-392"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-620"
                },
                {
                  "status": "affected",
                  "version": "13.0.5-007"
                },
                {
                  "status": "affected",
                  "version": "13.5.4-038"
                },
                {
                  "status": "affected",
                  "version": "14.2.1-020"
                },
                {
                  "status": "affected",
                  "version": "14.3.0-032"
                },
                {
                  "status": "affected",
                  "version": "15.0.0-104"
                },
                {
                  "status": "affected",
                  "version": "15.0.1-030"
                },
                {
                  "status": "affected",
                  "version": "15.5.0-048"
                },
                {
                  "status": "affected",
                  "version": "15.5.1-055"
                },
                {
                  "status": "affected",
                  "version": "15.5.2-018"
                },
                {
                  "status": "affected",
                  "version": "16.0.0-050"
                },
                {
                  "status": "affected",
                  "version": "15.0.3-002"
                },
                {
                  "status": "affected",
                  "version": "16.0.0-054"
                },
                {
                  "status": "affected",
                  "version": "15.5.3-022"
                },
                {
                  "status": "affected",
                  "version": "16.0.1-017"
                },
                {
                  "status": "affected",
                  "version": "15.5.4-012"
                },
                {
                  "status": "affected",
                  "version": "16.0.4-016"
                },
                {
                  "status": "affected",
                  "version": "15.0.5-016"
                },
                {
                  "status": "affected",
                  "version": "16.0.2-112"
                },
                {
                  "status": "affected",
                  "version": "16.0.3-044"
                },
                {
                  "status": "affected",
                  "version": "16.5.0-780"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "Cisco Secure Email and Web Manager",
              "vendor": "Cisco",
              "versions": [
                {
                  "status": "affected",
                  "version": "13.6.2-023"
                },
                {
                  "status": "affected",
                  "version": "13.6.2-078"
                },
                {
                  "status": "affected",
                  "version": "13.0.0-249"
                },
                {
                  "status": "affected",
                  "version": "13.0.0-277"
                },
                {
                  "status": "affected",
                  "version": "13.8.1-052"
                },
                {
                  "status": "affected",
                  "version": "13.8.1-068"
                },
                {
                  "status": "affected",
                  "version": "13.8.1-074"
                },
                {
                  "status": "affected",
                  "version": "14.0.0-404"
                },
                {
                  "status": "affected",
                  "version": "12.8.1-002"
                },
                {
                  "status": "affected",
                  "version": "14.1.0-227"
                },
                {
                  "status": "affected",
                  "version": "13.6.1-201"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-203"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-212"
                },
                {
                  "status": "affected",
                  "version": "12.8.1-021"
                },
                {
                  "status": "affected",
                  "version": "13.8.1-108"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-224"
                },
                {
                  "status": "affected",
                  "version": "14.3.0-120"
                },
                {
                  "status": "affected",
                  "version": "15.0.0-334"
                },
                {
                  "status": "affected",
                  "version": "15.5.1-024"
                },
                {
                  "status": "affected",
                  "version": "15.5.1-029"
                },
                {
                  "status": "affected",
                  "version": "15.5.2-005"
                },
                {
                  "status": "affected",
                  "version": "16.0.0-195"
                },
                {
                  "status": "affected",
                  "version": "15.5.3-017"
                },
                {
                  "status": "affected",
                  "version": "16.0.1-010"
                },
                {
                  "status": "affected",
                  "version": "15.0.1-035"
                },
                {
                  "status": "affected",
                  "version": "16.0.2-088"
                },
                {
                  "status": "affected",
                  "version": "15.5.4-007"
                },
                {
                  "status": "affected",
                  "version": "15.0.2-007"
                },
                {
                  "status": "affected",
                  "version": "16.0.4-010"
                },
                {
                  "status": "affected",
                  "version": "16.0.3-016"
                },
                {
                  "status": "affected",
                  "version": "16.5.0-429"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "As part of Cisco\u0027s ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-76442 are related to issues with improper validation of specified quantity in input that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-1284."
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "value": "Except as otherwise noted previously, the Cisco PSIRT is not aware of any public announcements or malicious use of the vulnerabilities that are described in this advisory."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "cvssV3_1"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-1284",
                  "description": "Improper Validation of Specified Quantity in Input",
                  "lang": "en",
                  "type": "cwe"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-14T16:09:08.878Z",
            "orgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
            "shortName": "cisco"
          },
          "references": [
            {
              "name": "cisco-sa-hardening-esa-dfCrfXkm",
              "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm"
            }
          ],
          "source": {
            "advisory": "cisco-sa-hardening-esa-dfCrfXkm",
            "defects": [
              "CSCwu56549"
            ],
            "discovery": "INTERNAL"
          },
          "title": "Cisco Secure Email Gateway Security Hardening Release"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
        "assignerShortName": "cisco",
        "cveId": "CVE-2026-76442",
        "datePublished": "2026-09-14T16:09:08.878Z",
        "dateReserved": "2026-08-19T12:02:03.635Z",
        "dateUpdated": "2026-09-16T03:55:36.952Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-76461 (GCVE-0-2026-76461)

    Vulnerability from cvelistv5 – Published: 2026-09-14 16:09 – Updated: 2026-09-18 12:10
    VLAI CISA Previdian
    Title
    Cisco Secure Email Gateway SQL Injection Vulnerability
    Summary
    A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.
    SSVC
    Exploitation: active Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-14 00:00 UTC
    CWE
    • CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
    Impacted products
    Vendor Product Version
    Cisco Cisco Secure Email Affected: 14.0.0-698
    Affected: 13.5.1-277
    Affected: 13.0.0-392
    Affected: 14.2.0-620
    Affected: 13.0.5-007
    Affected: 13.5.4-038
    Affected: 14.2.1-020
    Affected: 14.3.0-032
    Affected: 15.0.0-104
    Affected: 15.0.1-030
    Affected: 15.5.0-048
    Affected: 15.5.1-055
    Affected: 15.5.2-018
    Affected: 16.0.0-050
    Affected: 15.0.3-002
    Affected: 16.0.0-054
    Affected: 15.5.3-022
    Affected: 16.0.1-017
    Affected: 15.5.4-012
    Affected: 16.0.4-016
    Affected: 15.0.5-016
    Affected: 16.0.2-112
    Affected: 16.0.3-044
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-76461",
                    "options": [
                      {
                        "Exploitation": "active"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-14T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              },
              {
                "other": {
                  "content": {
                    "dateAdded": "2026-09-14",
                    "reference": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-76461"
                  },
                  "type": "kev"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-15T03:56:06.270Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "government-resource"
                ],
                "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-76461"
              }
            ],
            "timeline": [
              {
                "lang": "en",
                "time": "2026-09-14T00:00:00.000Z",
                "value": "CVE-2026-76461 added to CISA KEV"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "Cisco Secure Email",
              "vendor": "Cisco",
              "versions": [
                {
                  "status": "affected",
                  "version": "14.0.0-698"
                },
                {
                  "status": "affected",
                  "version": "13.5.1-277"
                },
                {
                  "status": "affected",
                  "version": "13.0.0-392"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-620"
                },
                {
                  "status": "affected",
                  "version": "13.0.5-007"
                },
                {
                  "status": "affected",
                  "version": "13.5.4-038"
                },
                {
                  "status": "affected",
                  "version": "14.2.1-020"
                },
                {
                  "status": "affected",
                  "version": "14.3.0-032"
                },
                {
                  "status": "affected",
                  "version": "15.0.0-104"
                },
                {
                  "status": "affected",
                  "version": "15.0.1-030"
                },
                {
                  "status": "affected",
                  "version": "15.5.0-048"
                },
                {
                  "status": "affected",
                  "version": "15.5.1-055"
                },
                {
                  "status": "affected",
                  "version": "15.5.2-018"
                },
                {
                  "status": "affected",
                  "version": "16.0.0-050"
                },
                {
                  "status": "affected",
                  "version": "15.0.3-002"
                },
                {
                  "status": "affected",
                  "version": "16.0.0-054"
                },
                {
                  "status": "affected",
                  "version": "15.5.3-022"
                },
                {
                  "status": "affected",
                  "version": "16.0.1-017"
                },
                {
                  "status": "affected",
                  "version": "15.5.4-012"
                },
                {
                  "status": "affected",
                  "version": "16.0.4-016"
                },
                {
                  "status": "affected",
                  "version": "15.0.5-016"
                },
                {
                  "status": "affected",
                  "version": "16.0.2-112"
                },
                {
                  "status": "affected",
                  "version": "16.0.3-044"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.\r\n\r\nThis vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system."
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "value": "In September 2026, the\u00a0Cisco PSIRT became aware of active exploitation of this vulnerability."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "cvssV3_1"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-89",
                  "description": "Improper Neutralization of Special Elements used in an SQL Command (\u0027SQL Injection\u0027)",
                  "lang": "en",
                  "type": "cwe"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-18T12:10:27.392Z",
            "orgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
            "shortName": "cisco"
          },
          "references": [
            {
              "name": "cisco-sa-esa-inj-2bLVGmhX",
              "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX"
            }
          ],
          "source": {
            "advisory": "cisco-sa-esa-inj-2bLVGmhX",
            "defects": [
              "CSCwu56234"
            ],
            "discovery": "INTERNAL"
          },
          "title": "Cisco Secure Email Gateway SQL Injection Vulnerability"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
        "assignerShortName": "cisco",
        "cveId": "CVE-2026-76461",
        "datePublished": "2026-09-14T16:09:07.839Z",
        "dateReserved": "2026-08-19T12:02:03.637Z",
        "dateUpdated": "2026-09-18T12:10:27.392Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-76443 (GCVE-0-2026-76443)

    Vulnerability from cvelistv5 – Published: 2026-09-14 16:08 – Updated: 2026-09-15 17:03
    VLAI
    Title
    Cisco Secure Email Gateway Security Hardening Release
    Summary
    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76443 are related to issues with improper neutralization that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-707.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-14 00:00 UTC
    CWE
    • CWE-707 - Improper Neutralization
    Impacted products
    Vendor Product Version
    Cisco Cisco Secure Email Affected: 14.0.0-698
    Affected: 13.5.1-277
    Affected: 13.0.0-392
    Affected: 14.2.0-620
    Affected: 13.0.5-007
    Affected: 13.5.4-038
    Affected: 14.2.1-020
    Affected: 14.3.0-032
    Affected: 15.0.0-104
    Affected: 15.0.1-030
    Affected: 15.5.0-048
    Affected: 15.5.1-055
    Affected: 15.5.2-018
    Affected: 16.0.0-050
    Affected: 15.0.3-002
    Affected: 16.0.0-054
    Affected: 15.5.3-022
    Affected: 16.0.1-017
    Affected: 15.5.4-012
    Affected: 16.0.4-016
    Affected: 15.0.5-016
    Affected: 16.0.2-112
    Affected: 16.0.3-044
    Create a notification for this product.
    Cisco Cisco Secure Email and Web Manager Affected: 13.6.2-023
    Affected: 13.6.2-078
    Affected: 13.0.0-249
    Affected: 13.0.0-277
    Affected: 13.8.1-052
    Affected: 13.8.1-068
    Affected: 13.8.1-074
    Affected: 14.0.0-404
    Affected: 12.8.1-002
    Affected: 14.1.0-227
    Affected: 13.6.1-201
    Affected: 14.2.0-203
    Affected: 14.2.0-212
    Affected: 12.8.1-021
    Affected: 13.8.1-108
    Affected: 14.2.0-224
    Affected: 14.3.0-120
    Affected: 15.0.0-334
    Affected: 15.5.1-024
    Affected: 15.5.1-029
    Affected: 15.5.2-005
    Affected: 16.0.0-195
    Affected: 15.5.3-017
    Affected: 16.0.1-010
    Affected: 15.0.1-035
    Affected: 16.0.2-088
    Affected: 15.5.4-007
    Affected: 15.0.2-007
    Affected: 16.0.4-010
    Affected: 16.0.3-016
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-76443",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-14T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-15T03:56:11.795Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "descriptions": [
              {
                "lang": "en",
                "value": "The CVE Program recognizes that this CVE Record provides vulnerability information that a Supplier CNA believes is very important to consumers. The CVE Program has flagged this CVE Record as it assigns a single CVE ID to a collection of individual vulnerabilities which does not align with CVE\u0027s \"one vulnerability, one ID\" principle, and therefore provides incomplete information. For further clarification, please see the CVE Program\u0027s blog, \"Preserving Vulnerability-Level Identification\" linked below. Details within the CNA container below are viewable by clicking on the CNA name."
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-15T17:03:58.065Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://www.cve.org/Media/News/item/blog/2026/06/16/Preserving-Vulnerability-Level-Identification"
              }
            ],
            "tags": [
              "x_bundling-flagged-by-CVE-Program"
            ]
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "Cisco Secure Email",
              "vendor": "Cisco",
              "versions": [
                {
                  "status": "affected",
                  "version": "14.0.0-698"
                },
                {
                  "status": "affected",
                  "version": "13.5.1-277"
                },
                {
                  "status": "affected",
                  "version": "13.0.0-392"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-620"
                },
                {
                  "status": "affected",
                  "version": "13.0.5-007"
                },
                {
                  "status": "affected",
                  "version": "13.5.4-038"
                },
                {
                  "status": "affected",
                  "version": "14.2.1-020"
                },
                {
                  "status": "affected",
                  "version": "14.3.0-032"
                },
                {
                  "status": "affected",
                  "version": "15.0.0-104"
                },
                {
                  "status": "affected",
                  "version": "15.0.1-030"
                },
                {
                  "status": "affected",
                  "version": "15.5.0-048"
                },
                {
                  "status": "affected",
                  "version": "15.5.1-055"
                },
                {
                  "status": "affected",
                  "version": "15.5.2-018"
                },
                {
                  "status": "affected",
                  "version": "16.0.0-050"
                },
                {
                  "status": "affected",
                  "version": "15.0.3-002"
                },
                {
                  "status": "affected",
                  "version": "16.0.0-054"
                },
                {
                  "status": "affected",
                  "version": "15.5.3-022"
                },
                {
                  "status": "affected",
                  "version": "16.0.1-017"
                },
                {
                  "status": "affected",
                  "version": "15.5.4-012"
                },
                {
                  "status": "affected",
                  "version": "16.0.4-016"
                },
                {
                  "status": "affected",
                  "version": "15.0.5-016"
                },
                {
                  "status": "affected",
                  "version": "16.0.2-112"
                },
                {
                  "status": "affected",
                  "version": "16.0.3-044"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "Cisco Secure Email and Web Manager",
              "vendor": "Cisco",
              "versions": [
                {
                  "status": "affected",
                  "version": "13.6.2-023"
                },
                {
                  "status": "affected",
                  "version": "13.6.2-078"
                },
                {
                  "status": "affected",
                  "version": "13.0.0-249"
                },
                {
                  "status": "affected",
                  "version": "13.0.0-277"
                },
                {
                  "status": "affected",
                  "version": "13.8.1-052"
                },
                {
                  "status": "affected",
                  "version": "13.8.1-068"
                },
                {
                  "status": "affected",
                  "version": "13.8.1-074"
                },
                {
                  "status": "affected",
                  "version": "14.0.0-404"
                },
                {
                  "status": "affected",
                  "version": "12.8.1-002"
                },
                {
                  "status": "affected",
                  "version": "14.1.0-227"
                },
                {
                  "status": "affected",
                  "version": "13.6.1-201"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-203"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-212"
                },
                {
                  "status": "affected",
                  "version": "12.8.1-021"
                },
                {
                  "status": "affected",
                  "version": "13.8.1-108"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-224"
                },
                {
                  "status": "affected",
                  "version": "14.3.0-120"
                },
                {
                  "status": "affected",
                  "version": "15.0.0-334"
                },
                {
                  "status": "affected",
                  "version": "15.5.1-024"
                },
                {
                  "status": "affected",
                  "version": "15.5.1-029"
                },
                {
                  "status": "affected",
                  "version": "15.5.2-005"
                },
                {
                  "status": "affected",
                  "version": "16.0.0-195"
                },
                {
                  "status": "affected",
                  "version": "15.5.3-017"
                },
                {
                  "status": "affected",
                  "version": "16.0.1-010"
                },
                {
                  "status": "affected",
                  "version": "15.0.1-035"
                },
                {
                  "status": "affected",
                  "version": "16.0.2-088"
                },
                {
                  "status": "affected",
                  "version": "15.5.4-007"
                },
                {
                  "status": "affected",
                  "version": "15.0.2-007"
                },
                {
                  "status": "affected",
                  "version": "16.0.4-010"
                },
                {
                  "status": "affected",
                  "version": "16.0.3-016"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "As part of Cisco\u0027s ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-76443 are related to issues with improper neutralization that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-707."
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "value": "Except as otherwise noted previously, the Cisco PSIRT is not aware of any public announcements or malicious use of the vulnerabilities that are described in this advisory."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "cvssV3_1"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-707",
                  "description": "Improper Neutralization",
                  "lang": "en",
                  "type": "cwe"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-14T16:08:59.278Z",
            "orgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
            "shortName": "cisco"
          },
          "references": [
            {
              "name": "cisco-sa-hardening-esa-dfCrfXkm",
              "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm"
            }
          ],
          "source": {
            "advisory": "cisco-sa-hardening-esa-dfCrfXkm",
            "defects": [
              "CSCwu56232"
            ],
            "discovery": "INTERNAL"
          },
          "title": "Cisco Secure Email Gateway Security Hardening Release"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
        "assignerShortName": "cisco",
        "cveId": "CVE-2026-76443",
        "datePublished": "2026-09-14T16:08:59.278Z",
        "dateReserved": "2026-08-19T12:02:03.635Z",
        "dateUpdated": "2026-09-15T17:03:58.065Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-76440 (GCVE-0-2026-76440)

    Vulnerability from cvelistv5 – Published: 2026-09-14 16:08 – Updated: 2026-09-15 17:03
    VLAI
    Title
    Cisco Secure Email Gateway Security Hardening Release
    Summary
    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76440 are related to path traversal issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-23.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-14 00:00 UTC
    CWE
    • CWE-23 - Relative Path Traversal
    Impacted products
    Vendor Product Version
    Cisco Cisco Secure Email Affected: 14.0.0-698
    Affected: 13.5.1-277
    Affected: 13.0.0-392
    Affected: 14.2.0-620
    Affected: 13.0.5-007
    Affected: 13.5.4-038
    Affected: 14.2.1-020
    Affected: 14.3.0-032
    Affected: 15.0.0-104
    Affected: 15.0.1-030
    Affected: 15.5.0-048
    Affected: 15.5.1-055
    Affected: 15.5.2-018
    Affected: 16.0.0-050
    Affected: 15.0.3-002
    Affected: 16.0.0-054
    Affected: 15.5.3-022
    Affected: 16.0.1-017
    Affected: 15.5.4-012
    Affected: 16.0.4-016
    Affected: 15.0.5-016
    Affected: 16.0.2-112
    Affected: 16.0.3-044
    Affected: 15.5.5-014
    Create a notification for this product.
    Cisco Cisco Secure Email and Web Manager Affected: 13.6.2-023
    Affected: 13.6.2-078
    Affected: 13.0.0-249
    Affected: 13.0.0-277
    Affected: 13.8.1-052
    Affected: 13.8.1-068
    Affected: 13.8.1-074
    Affected: 14.0.0-404
    Affected: 12.8.1-002
    Affected: 14.1.0-227
    Affected: 13.6.1-201
    Affected: 14.2.0-203
    Affected: 14.2.0-212
    Affected: 12.8.1-021
    Affected: 13.8.1-108
    Affected: 14.2.0-224
    Affected: 14.3.0-120
    Affected: 15.0.0-334
    Affected: 15.5.1-024
    Affected: 15.5.1-029
    Affected: 15.5.2-005
    Affected: 16.0.0-195
    Affected: 15.5.3-017
    Affected: 16.0.1-010
    Affected: 15.0.1-035
    Affected: 16.0.2-088
    Affected: 15.5.4-007
    Affected: 15.0.2-007
    Affected: 16.0.4-010
    Affected: 16.0.3-016
    Affected: 16.5.0-429
    Affected: 15.5.5-006
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-76440",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-14T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-15T03:56:08.458Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "descriptions": [
              {
                "lang": "en",
                "value": "The CVE Program recognizes that this CVE Record provides vulnerability information that a Supplier CNA believes is very important to consumers. The CVE Program has flagged this CVE Record as it assigns a single CVE ID to a collection of individual vulnerabilities which does not align with CVE\u0027s \"one vulnerability, one ID\" principle, and therefore provides incomplete information. For further clarification, please see the CVE Program\u0027s blog, \"Preserving Vulnerability-Level Identification\" linked below. Details within the CNA container below are viewable by clicking on the CNA name."
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-15T17:03:57.728Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://www.cve.org/Media/News/item/blog/2026/06/16/Preserving-Vulnerability-Level-Identification"
              }
            ],
            "tags": [
              "x_bundling-flagged-by-CVE-Program"
            ]
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "Cisco Secure Email",
              "vendor": "Cisco",
              "versions": [
                {
                  "status": "affected",
                  "version": "14.0.0-698"
                },
                {
                  "status": "affected",
                  "version": "13.5.1-277"
                },
                {
                  "status": "affected",
                  "version": "13.0.0-392"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-620"
                },
                {
                  "status": "affected",
                  "version": "13.0.5-007"
                },
                {
                  "status": "affected",
                  "version": "13.5.4-038"
                },
                {
                  "status": "affected",
                  "version": "14.2.1-020"
                },
                {
                  "status": "affected",
                  "version": "14.3.0-032"
                },
                {
                  "status": "affected",
                  "version": "15.0.0-104"
                },
                {
                  "status": "affected",
                  "version": "15.0.1-030"
                },
                {
                  "status": "affected",
                  "version": "15.5.0-048"
                },
                {
                  "status": "affected",
                  "version": "15.5.1-055"
                },
                {
                  "status": "affected",
                  "version": "15.5.2-018"
                },
                {
                  "status": "affected",
                  "version": "16.0.0-050"
                },
                {
                  "status": "affected",
                  "version": "15.0.3-002"
                },
                {
                  "status": "affected",
                  "version": "16.0.0-054"
                },
                {
                  "status": "affected",
                  "version": "15.5.3-022"
                },
                {
                  "status": "affected",
                  "version": "16.0.1-017"
                },
                {
                  "status": "affected",
                  "version": "15.5.4-012"
                },
                {
                  "status": "affected",
                  "version": "16.0.4-016"
                },
                {
                  "status": "affected",
                  "version": "15.0.5-016"
                },
                {
                  "status": "affected",
                  "version": "16.0.2-112"
                },
                {
                  "status": "affected",
                  "version": "16.0.3-044"
                },
                {
                  "status": "affected",
                  "version": "15.5.5-014"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "Cisco Secure Email and Web Manager",
              "vendor": "Cisco",
              "versions": [
                {
                  "status": "affected",
                  "version": "13.6.2-023"
                },
                {
                  "status": "affected",
                  "version": "13.6.2-078"
                },
                {
                  "status": "affected",
                  "version": "13.0.0-249"
                },
                {
                  "status": "affected",
                  "version": "13.0.0-277"
                },
                {
                  "status": "affected",
                  "version": "13.8.1-052"
                },
                {
                  "status": "affected",
                  "version": "13.8.1-068"
                },
                {
                  "status": "affected",
                  "version": "13.8.1-074"
                },
                {
                  "status": "affected",
                  "version": "14.0.0-404"
                },
                {
                  "status": "affected",
                  "version": "12.8.1-002"
                },
                {
                  "status": "affected",
                  "version": "14.1.0-227"
                },
                {
                  "status": "affected",
                  "version": "13.6.1-201"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-203"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-212"
                },
                {
                  "status": "affected",
                  "version": "12.8.1-021"
                },
                {
                  "status": "affected",
                  "version": "13.8.1-108"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-224"
                },
                {
                  "status": "affected",
                  "version": "14.3.0-120"
                },
                {
                  "status": "affected",
                  "version": "15.0.0-334"
                },
                {
                  "status": "affected",
                  "version": "15.5.1-024"
                },
                {
                  "status": "affected",
                  "version": "15.5.1-029"
                },
                {
                  "status": "affected",
                  "version": "15.5.2-005"
                },
                {
                  "status": "affected",
                  "version": "16.0.0-195"
                },
                {
                  "status": "affected",
                  "version": "15.5.3-017"
                },
                {
                  "status": "affected",
                  "version": "16.0.1-010"
                },
                {
                  "status": "affected",
                  "version": "15.0.1-035"
                },
                {
                  "status": "affected",
                  "version": "16.0.2-088"
                },
                {
                  "status": "affected",
                  "version": "15.5.4-007"
                },
                {
                  "status": "affected",
                  "version": "15.0.2-007"
                },
                {
                  "status": "affected",
                  "version": "16.0.4-010"
                },
                {
                  "status": "affected",
                  "version": "16.0.3-016"
                },
                {
                  "status": "affected",
                  "version": "16.5.0-429"
                },
                {
                  "status": "affected",
                  "version": "15.5.5-006"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "As part of Cisco\u0027s ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-76440 are related to path traversal issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-23."
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "value": "Except as otherwise noted previously, the Cisco PSIRT is not aware of any public announcements or malicious use of the vulnerabilities that are described in this advisory."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "cvssV3_1"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-23",
                  "description": "Relative Path Traversal",
                  "lang": "en",
                  "type": "cwe"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-14T16:08:50.075Z",
            "orgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
            "shortName": "cisco"
          },
          "references": [
            {
              "name": "cisco-sa-hardening-esa-dfCrfXkm",
              "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm"
            }
          ],
          "source": {
            "advisory": "cisco-sa-hardening-esa-dfCrfXkm",
            "defects": [
              "CSCwu56221"
            ],
            "discovery": "INTERNAL"
          },
          "title": "Cisco Secure Email Gateway Security Hardening Release"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
        "assignerShortName": "cisco",
        "cveId": "CVE-2026-76440",
        "datePublished": "2026-09-14T16:08:50.075Z",
        "dateReserved": "2026-08-19T12:02:03.635Z",
        "dateUpdated": "2026-09-15T17:03:57.728Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-20353 (GCVE-0-2026-20353)

    Vulnerability from cvelistv5 – Published: 2026-09-14 16:08 – Updated: 2026-09-15 17:03
    VLAI
    Title
    Cisco Secure Email Gateway Security Hardening Release
    Summary
    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20353 are related to issues with improper control of a resource through its lifetime that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-664.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-14 00:00 UTC
    CWE
    • CWE-664 - Improper Control of a Resource Through its Lifetime
    Impacted products
    Vendor Product Version
    Cisco Cisco Secure Email Affected: 14.0.0-698
    Affected: 13.5.1-277
    Affected: 13.0.0-392
    Affected: 14.2.0-620
    Affected: 13.0.5-007
    Affected: 13.5.4-038
    Affected: 14.2.1-020
    Affected: 14.3.0-032
    Affected: 15.0.0-104
    Affected: 15.0.1-030
    Affected: 15.5.0-048
    Affected: 15.5.1-055
    Affected: 15.5.2-018
    Affected: 16.0.0-050
    Affected: 15.0.3-002
    Affected: 16.0.0-054
    Affected: 15.5.3-022
    Affected: 16.0.1-017
    Affected: 15.5.4-012
    Affected: 16.0.4-016
    Affected: 15.0.5-016
    Affected: 16.0.2-112
    Affected: 16.0.3-044
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-20353",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-14T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-15T03:56:07.357Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "descriptions": [
              {
                "lang": "en",
                "value": "The CVE Program recognizes that this CVE Record provides vulnerability information that a Supplier CNA believes is very important to consumers. The CVE Program has flagged this CVE Record as it assigns a single CVE ID to a collection of individual vulnerabilities which does not align with CVE\u0027s \"one vulnerability, one ID\" principle, and therefore provides incomplete information. For further clarification, please see the CVE Program\u0027s blog, \"Preserving Vulnerability-Level Identification\" linked below. Details within the CNA container below are viewable by clicking on the CNA name."
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-15T17:03:57.940Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://www.cve.org/Media/News/item/blog/2026/06/16/Preserving-Vulnerability-Level-Identification"
              }
            ],
            "tags": [
              "x_bundling-flagged-by-CVE-Program"
            ]
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "Cisco Secure Email",
              "vendor": "Cisco",
              "versions": [
                {
                  "status": "affected",
                  "version": "14.0.0-698"
                },
                {
                  "status": "affected",
                  "version": "13.5.1-277"
                },
                {
                  "status": "affected",
                  "version": "13.0.0-392"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-620"
                },
                {
                  "status": "affected",
                  "version": "13.0.5-007"
                },
                {
                  "status": "affected",
                  "version": "13.5.4-038"
                },
                {
                  "status": "affected",
                  "version": "14.2.1-020"
                },
                {
                  "status": "affected",
                  "version": "14.3.0-032"
                },
                {
                  "status": "affected",
                  "version": "15.0.0-104"
                },
                {
                  "status": "affected",
                  "version": "15.0.1-030"
                },
                {
                  "status": "affected",
                  "version": "15.5.0-048"
                },
                {
                  "status": "affected",
                  "version": "15.5.1-055"
                },
                {
                  "status": "affected",
                  "version": "15.5.2-018"
                },
                {
                  "status": "affected",
                  "version": "16.0.0-050"
                },
                {
                  "status": "affected",
                  "version": "15.0.3-002"
                },
                {
                  "status": "affected",
                  "version": "16.0.0-054"
                },
                {
                  "status": "affected",
                  "version": "15.5.3-022"
                },
                {
                  "status": "affected",
                  "version": "16.0.1-017"
                },
                {
                  "status": "affected",
                  "version": "15.5.4-012"
                },
                {
                  "status": "affected",
                  "version": "16.0.4-016"
                },
                {
                  "status": "affected",
                  "version": "15.0.5-016"
                },
                {
                  "status": "affected",
                  "version": "16.0.2-112"
                },
                {
                  "status": "affected",
                  "version": "16.0.3-044"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "As part of Cisco\u0027s ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-20353 are related to issues with improper control of a resource through its lifetime that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-664."
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "value": "Except as otherwise noted previously, the Cisco PSIRT is not aware of any public announcements or malicious use of the vulnerabilities that are described in this advisory."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "cvssV3_1"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-664",
                  "description": "Improper Control of a Resource Through its Lifetime",
                  "lang": "en",
                  "type": "cwe"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-14T16:08:50.062Z",
            "orgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
            "shortName": "cisco"
          },
          "references": [
            {
              "name": "cisco-sa-hardening-esa-dfCrfXkm",
              "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm"
            }
          ],
          "source": {
            "advisory": "cisco-sa-hardening-esa-dfCrfXkm",
            "defects": [
              "CSCwu68894"
            ],
            "discovery": "INTERNAL"
          },
          "title": "Cisco Secure Email Gateway Security Hardening Release"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
        "assignerShortName": "cisco",
        "cveId": "CVE-2026-20353",
        "datePublished": "2026-09-14T16:08:50.062Z",
        "dateReserved": "2025-10-08T11:59:15.414Z",
        "dateUpdated": "2026-09-15T17:03:57.940Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-20355 (GCVE-0-2026-20355)

    Vulnerability from cvelistv5 – Published: 2026-09-02 16:14 – Updated: 2026-09-08 16:04
    VLAI
    Title
    Cisco Secure Email S/MIME Ciphertext Decryption Vulnerabilty
    Summary
    Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages. These vulnerabilities are due to insufficient validation of message integrity. An attacker could exploit these vulnerabilities by using a machine-in-the-middle technique to intercept and modify traffic between email gateways. A successful exploit could allow the attacker to obtain plaintext content from the encrypted communication.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-02 16:49 UTC
    CWE
    • CWE-345 - Insufficient Verification of Data Authenticity
    Impacted products
    Vendor Product Version
    Cisco Cisco Secure Email Affected: 14.0.0-698
    Affected: 13.5.1-277
    Affected: 13.0.0-392
    Affected: 14.2.0-620
    Affected: 13.0.5-007
    Affected: 13.5.4-038
    Affected: 14.2.1-020
    Affected: 14.3.0-032
    Affected: 15.0.0-104
    Affected: 15.0.1-030
    Affected: 15.5.0-048
    Affected: 15.5.1-055
    Affected: 15.5.2-018
    Affected: 16.0.0-050
    Affected: 15.0.3-002
    Affected: 16.0.0-054
    Affected: 15.5.3-022
    Affected: 16.0.1-017
    Affected: 15.5.4-012
    Affected: 16.0.4-016
    Affected: 15.0.5-016
    Affected: 16.0.2-112
    Affected: 16.0.3-044
    Affected: 16.5.0-780
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-20355",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-02T16:49:13.406894Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-02T17:58:57.899Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "Cisco Secure Email",
              "vendor": "Cisco",
              "versions": [
                {
                  "status": "affected",
                  "version": "14.0.0-698"
                },
                {
                  "status": "affected",
                  "version": "13.5.1-277"
                },
                {
                  "status": "affected",
                  "version": "13.0.0-392"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-620"
                },
                {
                  "status": "affected",
                  "version": "13.0.5-007"
                },
                {
                  "status": "affected",
                  "version": "13.5.4-038"
                },
                {
                  "status": "affected",
                  "version": "14.2.1-020"
                },
                {
                  "status": "affected",
                  "version": "14.3.0-032"
                },
                {
                  "status": "affected",
                  "version": "15.0.0-104"
                },
                {
                  "status": "affected",
                  "version": "15.0.1-030"
                },
                {
                  "status": "affected",
                  "version": "15.5.0-048"
                },
                {
                  "status": "affected",
                  "version": "15.5.1-055"
                },
                {
                  "status": "affected",
                  "version": "15.5.2-018"
                },
                {
                  "status": "affected",
                  "version": "16.0.0-050"
                },
                {
                  "status": "affected",
                  "version": "15.0.3-002"
                },
                {
                  "status": "affected",
                  "version": "16.0.0-054"
                },
                {
                  "status": "affected",
                  "version": "15.5.3-022"
                },
                {
                  "status": "affected",
                  "version": "16.0.1-017"
                },
                {
                  "status": "affected",
                  "version": "15.5.4-012"
                },
                {
                  "status": "affected",
                  "version": "16.0.4-016"
                },
                {
                  "status": "affected",
                  "version": "15.0.5-016"
                },
                {
                  "status": "affected",
                  "version": "16.0.2-112"
                },
                {
                  "status": "affected",
                  "version": "16.0.3-044"
                },
                {
                  "status": "affected",
                  "version": "16.5.0-780"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages.\r\n\r\nThese vulnerabilities are due to insufficient validation of message integrity. An attacker could exploit these vulnerabilities by using a machine-in-the-middle technique to intercept and modify traffic between email gateways. A successful exploit could allow the attacker to obtain plaintext content from the encrypted communication."
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "value": "The Cisco Product Security Incident Response Team (PSIRT) is aware that a public announcement is available for the vulnerabilities that are described in this advisory.\r\n\r\nThe Cisco PSIRT is not aware of any malicious use of the vulnerabilities that are described in this advisory."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.9,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "cvssV3_1"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-345",
                  "description": "Insufficient Verification of Data Authenticity",
                  "lang": "en",
                  "type": "cwe"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-08T16:04:40.505Z",
            "orgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
            "shortName": "cisco"
          },
          "references": [
            {
              "name": "cisco-sa-esa-smime-disc-dzw4rEdY",
              "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-smime-disc-dzw4rEdY"
            }
          ],
          "source": {
            "advisory": "cisco-sa-esa-smime-disc-dzw4rEdY",
            "defects": [
              "CSCwu28362"
            ],
            "discovery": "EXTERNAL"
          },
          "title": "Cisco Secure Email S/MIME Ciphertext Decryption Vulnerabilty"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
        "assignerShortName": "cisco",
        "cveId": "CVE-2026-20355",
        "datePublished": "2026-09-02T16:14:32.732Z",
        "dateReserved": "2025-10-08T11:59:15.414Z",
        "dateUpdated": "2026-09-08T16:04:40.505Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-20354 (GCVE-0-2026-20354)

    Vulnerability from cvelistv5 – Published: 2026-09-02 16:14 – Updated: 2026-09-02 17:58
    VLAI
    Title
    Cisco Secure Email S/MIME Ciphertext Decryption Vulnerabilty
    Summary
    Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages. These vulnerabilities are due to insufficient validation of message integrity. An attacker could exploit these vulnerabilities by using a machine-in-the-middle technique to intercept and modify traffic between email gateways. A successful exploit could allow the attacker to obtain plaintext content from the encrypted communication.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-02 16:49 UTC
    CWE
    • CWE-354 - Improper Validation of Integrity Check Value
    Impacted products
    Vendor Product Version
    Cisco Cisco Secure Email Affected: 14.0.0-698
    Affected: 13.5.1-277
    Affected: 13.0.0-392
    Affected: 14.2.0-620
    Affected: 13.0.5-007
    Affected: 13.5.4-038
    Affected: 14.2.1-020
    Affected: 14.3.0-032
    Affected: 15.0.0-104
    Affected: 15.0.1-030
    Affected: 15.5.0-048
    Affected: 15.5.1-055
    Affected: 15.5.2-018
    Affected: 16.0.0-050
    Affected: 15.0.3-002
    Affected: 16.0.0-054
    Affected: 15.5.3-022
    Affected: 16.0.1-017
    Affected: 15.5.4-012
    Affected: 16.0.4-016
    Affected: 15.0.5-016
    Affected: 16.0.2-112
    Affected: 16.0.3-044
    Affected: 16.5.0-780
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-20354",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-02T16:49:02.578484Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-02T17:58:58.074Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "Cisco Secure Email",
              "vendor": "Cisco",
              "versions": [
                {
                  "status": "affected",
                  "version": "14.0.0-698"
                },
                {
                  "status": "affected",
                  "version": "13.5.1-277"
                },
                {
                  "status": "affected",
                  "version": "13.0.0-392"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-620"
                },
                {
                  "status": "affected",
                  "version": "13.0.5-007"
                },
                {
                  "status": "affected",
                  "version": "13.5.4-038"
                },
                {
                  "status": "affected",
                  "version": "14.2.1-020"
                },
                {
                  "status": "affected",
                  "version": "14.3.0-032"
                },
                {
                  "status": "affected",
                  "version": "15.0.0-104"
                },
                {
                  "status": "affected",
                  "version": "15.0.1-030"
                },
                {
                  "status": "affected",
                  "version": "15.5.0-048"
                },
                {
                  "status": "affected",
                  "version": "15.5.1-055"
                },
                {
                  "status": "affected",
                  "version": "15.5.2-018"
                },
                {
                  "status": "affected",
                  "version": "16.0.0-050"
                },
                {
                  "status": "affected",
                  "version": "15.0.3-002"
                },
                {
                  "status": "affected",
                  "version": "16.0.0-054"
                },
                {
                  "status": "affected",
                  "version": "15.5.3-022"
                },
                {
                  "status": "affected",
                  "version": "16.0.1-017"
                },
                {
                  "status": "affected",
                  "version": "15.5.4-012"
                },
                {
                  "status": "affected",
                  "version": "16.0.4-016"
                },
                {
                  "status": "affected",
                  "version": "15.0.5-016"
                },
                {
                  "status": "affected",
                  "version": "16.0.2-112"
                },
                {
                  "status": "affected",
                  "version": "16.0.3-044"
                },
                {
                  "status": "affected",
                  "version": "16.5.0-780"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages.\r\n\r\nThese vulnerabilities are due to insufficient validation of message integrity. An attacker could exploit these vulnerabilities by using a machine-in-the-middle technique to intercept and modify traffic between email gateways. A successful exploit could allow the attacker to obtain plaintext content from the encrypted communication."
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "value": "The Cisco Product Security Incident Response Team (PSIRT) is aware that a public announcement is available for the vulnerabilities that are described in this advisory.\r\n\r\nThe Cisco PSIRT is not aware of any malicious use of the vulnerabilities that are described in this advisory."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.9,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "cvssV3_1"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-354",
                  "description": "Improper Validation of Integrity Check Value",
                  "lang": "en",
                  "type": "cwe"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-02T16:14:29.829Z",
            "orgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
            "shortName": "cisco"
          },
          "references": [
            {
              "name": "cisco-sa-esa-smime-disc-dzw4rEdY",
              "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-smime-disc-dzw4rEdY"
            }
          ],
          "source": {
            "advisory": "cisco-sa-esa-smime-disc-dzw4rEdY",
            "defects": [
              "CSCwu28364"
            ],
            "discovery": "EXTERNAL"
          },
          "title": "Cisco Secure Email S/MIME Ciphertext Decryption Vulnerabilty"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
        "assignerShortName": "cisco",
        "cveId": "CVE-2026-20354",
        "datePublished": "2026-09-02T16:14:29.829Z",
        "dateReserved": "2025-10-08T11:59:15.414Z",
        "dateUpdated": "2026-09-02T17:58:58.074Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-20393 (GCVE-0-2025-20393)

    Vulnerability from cvelistv5 – Published: 2025-12-17 16:47 – Updated: 2026-02-26 16:07
    VLAI CISA Previdian
    Title
    Cisco Secure Email Gateway and Cisco Secure Email and Web Manager Remote Command Execution Vulnerability
    Summary
    A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to execute arbitrary system commands on an affected device with root privileges. This vulnerability is due to insufficient validation of HTTP requests by the Spam Quarantine feature. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with root privileges.
    SSVC
    Exploitation: active Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-12-18 04:55 UTC
    CWE
    • CWE-20 - Improper Input Validation
    Impacted products
    Vendor Product Version
    Cisco Cisco Secure Email Affected: 14.0.0-698
    Affected: 13.5.1-277
    Affected: 13.0.0-392
    Affected: 14.2.0-620
    Affected: 13.0.5-007
    Affected: 13.5.4-038
    Affected: 14.2.1-020
    Affected: 14.3.0-032
    Affected: 15.0.0-104
    Affected: 15.0.1-030
    Affected: 15.5.0-048
    Affected: 15.5.1-055
    Affected: 15.5.2-018
    Affected: 16.0.0-050
    Affected: 15.0.3-002
    Affected: 16.0.0-054
    Affected: 15.5.3-022
    Affected: 16.0.1-017
    Create a notification for this product.
    Cisco Cisco Secure Email and Web Manager Affected: 13.6.2-023
    Affected: 13.6.2-078
    Affected: 13.0.0-249
    Affected: 13.0.0-277
    Affected: 13.8.1-052
    Affected: 13.8.1-068
    Affected: 13.8.1-074
    Affected: 14.0.0-404
    Affected: 12.8.1-002
    Affected: 14.1.0-227
    Affected: 13.6.1-201
    Affected: 14.2.0-203
    Affected: 14.2.0-212
    Affected: 12.8.1-021
    Affected: 13.8.1-108
    Affected: 14.2.0-224
    Affected: 14.3.0-120
    Affected: 15.0.0-334
    Affected: 15.5.1-024
    Affected: 15.5.1-029
    Affected: 15.5.2-005
    Affected: 16.0.0-195
    Affected: 15.5.3-017
    Affected: 16.0.1-010
    Affected: 15.0.1-035
    Affected: 16.0.2-088
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-20393",
                    "options": [
                      {
                        "Exploitation": "active"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-12-18T04:55:22.327258Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              },
              {
                "other": {
                  "content": {
                    "dateAdded": "2025-12-17",
                    "reference": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-20393"
                  },
                  "type": "kev"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-02-26T16:07:31.045Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "government-resource"
                ],
                "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-20393"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "Cisco Secure Email",
              "vendor": "Cisco",
              "versions": [
                {
                  "status": "affected",
                  "version": "14.0.0-698"
                },
                {
                  "status": "affected",
                  "version": "13.5.1-277"
                },
                {
                  "status": "affected",
                  "version": "13.0.0-392"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-620"
                },
                {
                  "status": "affected",
                  "version": "13.0.5-007"
                },
                {
                  "status": "affected",
                  "version": "13.5.4-038"
                },
                {
                  "status": "affected",
                  "version": "14.2.1-020"
                },
                {
                  "status": "affected",
                  "version": "14.3.0-032"
                },
                {
                  "status": "affected",
                  "version": "15.0.0-104"
                },
                {
                  "status": "affected",
                  "version": "15.0.1-030"
                },
                {
                  "status": "affected",
                  "version": "15.5.0-048"
                },
                {
                  "status": "affected",
                  "version": "15.5.1-055"
                },
                {
                  "status": "affected",
                  "version": "15.5.2-018"
                },
                {
                  "status": "affected",
                  "version": "16.0.0-050"
                },
                {
                  "status": "affected",
                  "version": "15.0.3-002"
                },
                {
                  "status": "affected",
                  "version": "16.0.0-054"
                },
                {
                  "status": "affected",
                  "version": "15.5.3-022"
                },
                {
                  "status": "affected",
                  "version": "16.0.1-017"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "Cisco Secure Email and Web Manager",
              "vendor": "Cisco",
              "versions": [
                {
                  "status": "affected",
                  "version": "13.6.2-023"
                },
                {
                  "status": "affected",
                  "version": "13.6.2-078"
                },
                {
                  "status": "affected",
                  "version": "13.0.0-249"
                },
                {
                  "status": "affected",
                  "version": "13.0.0-277"
                },
                {
                  "status": "affected",
                  "version": "13.8.1-052"
                },
                {
                  "status": "affected",
                  "version": "13.8.1-068"
                },
                {
                  "status": "affected",
                  "version": "13.8.1-074"
                },
                {
                  "status": "affected",
                  "version": "14.0.0-404"
                },
                {
                  "status": "affected",
                  "version": "12.8.1-002"
                },
                {
                  "status": "affected",
                  "version": "14.1.0-227"
                },
                {
                  "status": "affected",
                  "version": "13.6.1-201"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-203"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-212"
                },
                {
                  "status": "affected",
                  "version": "12.8.1-021"
                },
                {
                  "status": "affected",
                  "version": "13.8.1-108"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-224"
                },
                {
                  "status": "affected",
                  "version": "14.3.0-120"
                },
                {
                  "status": "affected",
                  "version": "15.0.0-334"
                },
                {
                  "status": "affected",
                  "version": "15.5.1-024"
                },
                {
                  "status": "affected",
                  "version": "15.5.1-029"
                },
                {
                  "status": "affected",
                  "version": "15.5.2-005"
                },
                {
                  "status": "affected",
                  "version": "16.0.0-195"
                },
                {
                  "status": "affected",
                  "version": "15.5.3-017"
                },
                {
                  "status": "affected",
                  "version": "16.0.1-010"
                },
                {
                  "status": "affected",
                  "version": "15.0.1-035"
                },
                {
                  "status": "affected",
                  "version": "16.0.2-088"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to execute arbitrary system commands on an affected device with root privileges.\r\n\r\nThis vulnerability is due to insufficient validation of HTTP requests by the Spam Quarantine feature. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with\u0026nbsp;root privileges."
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "value": "In December 2025, the Cisco Product Security Incident Response Team (PSIRT) became aware of potentially malicious activity that targets Cisco Secure Email Gateway and Cisco Secure Email and Web Manager appliances."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 10,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "cvssV3_1"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-20",
                  "description": "Improper Input Validation",
                  "lang": "en",
                  "type": "cwe"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-01-15T16:32:03.740Z",
            "orgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
            "shortName": "cisco"
          },
          "references": [
            {
              "name": "cisco-sa-sma-attack-N9bf4",
              "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sma-attack-N9bf4"
            }
          ],
          "source": {
            "advisory": "cisco-sa-sma-attack-N9bf4",
            "defects": [
              "CSCws36549"
            ],
            "discovery": "EXTERNAL"
          },
          "title": "Cisco Secure Email Gateway and Cisco Secure Email and Web Manager Remote Command Execution Vulnerability"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
        "assignerShortName": "cisco",
        "cveId": "CVE-2025-20393",
        "datePublished": "2025-12-17T16:47:13.128Z",
        "dateReserved": "2024-10-10T19:15:13.266Z",
        "dateUpdated": "2026-02-26T16:07:31.045Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-20153 (GCVE-0-2025-20153)

    Vulnerability from cvelistv5 – Published: 2025-02-19 16:06 – Updated: 2025-02-19 16:19
    VLAI
    Title
    Cisco ESA mail Bypass
    Summary
    A vulnerability in the email filtering mechanism of Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to bypass the configured rules and allow emails that should have been denied to flow through an affected device.   This vulnerability is due to improper handling of email that passes through an affected device. An attacker could exploit this vulnerability by sending a crafted email through the affected device. A successful exploit could allow the attacker to bypass email filters on the affected device.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-02-19 16:19 UTC
    CWE
    • CWE-284 - Improper Access Control
    Impacted products
    Vendor Product Version
    Cisco Cisco Secure Email Affected: 14.0.0-698
    Affected: 13.5.1-277
    Affected: 13.0.0-392
    Affected: 14.2.0-620
    Affected: 13.0.5-007
    Affected: 13.5.4-038
    Affected: 14.2.1-020
    Affected: 14.3.0-032
    Affected: 15.0.0-104
    Affected: 15.0.1-030
    Affected: 15.5.0-048
    Affected: 15.5.1-055
    Affected: 15.5.2-018
    Affected: 16.0.0-050
    Affected: 15.0.3-002
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-20153",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-02-19T16:19:02.308539Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-02-19T16:19:19.168Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "Cisco Secure Email",
              "vendor": "Cisco",
              "versions": [
                {
                  "status": "affected",
                  "version": "14.0.0-698"
                },
                {
                  "status": "affected",
                  "version": "13.5.1-277"
                },
                {
                  "status": "affected",
                  "version": "13.0.0-392"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-620"
                },
                {
                  "status": "affected",
                  "version": "13.0.5-007"
                },
                {
                  "status": "affected",
                  "version": "13.5.4-038"
                },
                {
                  "status": "affected",
                  "version": "14.2.1-020"
                },
                {
                  "status": "affected",
                  "version": "14.3.0-032"
                },
                {
                  "status": "affected",
                  "version": "15.0.0-104"
                },
                {
                  "status": "affected",
                  "version": "15.0.1-030"
                },
                {
                  "status": "affected",
                  "version": "15.5.0-048"
                },
                {
                  "status": "affected",
                  "version": "15.5.1-055"
                },
                {
                  "status": "affected",
                  "version": "15.5.2-018"
                },
                {
                  "status": "affected",
                  "version": "16.0.0-050"
                },
                {
                  "status": "affected",
                  "version": "15.0.3-002"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability in the email filtering mechanism of Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to bypass the configured rules and allow emails that should have been denied to flow through an affected device. \u0026nbsp;\r\n\r\nThis vulnerability is due to improper handling of email that passes through an affected device. An attacker could exploit this vulnerability by sending a crafted email through the affected device. A successful exploit could allow the attacker to bypass email filters on the affected device."
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "value": "The Cisco PSIRT is not aware of any public announcements or malicious use of the vulnerability that is described in this advisory."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.8,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N",
                "version": "3.1"
              },
              "format": "cvssV3_1"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-284",
                  "description": "Improper Access Control",
                  "lang": "en",
                  "type": "cwe"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-02-19T16:06:10.664Z",
            "orgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
            "shortName": "cisco"
          },
          "references": [
            {
              "name": "cisco-sa-esa-mailpol-bypass-5nVcJZMw",
              "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-mailpol-bypass-5nVcJZMw"
            }
          ],
          "source": {
            "advisory": "cisco-sa-esa-mailpol-bypass-5nVcJZMw",
            "defects": [
              "CSCwm82380"
            ],
            "discovery": "INTERNAL"
          },
          "title": "Cisco ESA mail Bypass"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
        "assignerShortName": "cisco",
        "cveId": "CVE-2025-20153",
        "datePublished": "2025-02-19T16:06:10.664Z",
        "dateReserved": "2024-10-10T19:15:13.216Z",
        "dateUpdated": "2025-02-19T16:19:19.168Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2025-20207 (GCVE-0-2025-20207)

    Vulnerability from cvelistv5 – Published: 2025-02-05 16:15 – Updated: 2025-02-05 16:57
    VLAI
    Title
    Cisco Secure Email Gateway, Cisco Secure Email and Web Appliance and Cisco Secure Web Appliance SNMP Polling Information Disclosure Vulnerability
    Summary
    A vulnerability in Simple Network Management Protocol (SNMP) polling for Cisco Secure Email and Web Manager, Cisco Secure Email Gateway, and Cisco Secure Web Appliance could allow an authenticated, remote attacker to obtain confidential information about the underlying operating system. This vulnerability exists because the appliances do not protect confidential information at rest in response to SNMP poll requests. An attacker could exploit this vulnerability by sending a crafted SNMP poll request to the affected appliance. A successful exploit could allow the attacker to discover confidential information that should be restricted. To exploit this vulnerability, an attacker must have the configured SNMP credentials.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-02-05 16:57 UTC
    CWE
    • CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor
    Impacted products
    Vendor Product Version
    Cisco Cisco Secure Email Affected: 14.0.0-698
    Affected: 13.5.1-277
    Affected: 13.0.0-392
    Affected: 14.2.0-620
    Affected: 13.0.5-007
    Affected: 13.5.4-038
    Affected: 14.2.1-020
    Affected: 14.3.0-032
    Affected: 15.0.0-104
    Affected: 15.0.1-030
    Affected: 15.5.0-048
    Affected: 15.5.1-055
    Create a notification for this product.
    Cisco Cisco Secure Email and Web Manager Affected: 13.6.2-023
    Affected: 13.6.2-078
    Affected: 13.0.0-249
    Affected: 13.0.0-277
    Affected: 13.8.1-052
    Affected: 13.8.1-068
    Affected: 13.8.1-074
    Affected: 14.0.0-404
    Affected: 12.8.1-002
    Affected: 14.1.0-227
    Affected: 13.6.1-201
    Affected: 14.2.0-203
    Affected: 14.2.0-212
    Affected: 12.8.1-021
    Affected: 13.8.1-108
    Affected: 14.2.0-224
    Affected: 14.3.0-120
    Affected: 15.0.0-334
    Affected: 15.5.1-024
    Affected: 15.5.1-029
    Create a notification for this product.
    Cisco Cisco Secure Web Appliance Affected: 11.8.0-453
    Affected: 12.5.3-002
    Affected: 12.0.3-007
    Affected: 12.0.3-005
    Affected: 14.1.0-032
    Affected: 14.1.0-047
    Affected: 14.1.0-041
    Affected: 12.0.4-002
    Affected: 14.0.2-012
    Affected: 11.8.0-414
    Affected: 12.0.1-268
    Affected: 11.8.1-023
    Affected: 11.8.3-021
    Affected: 11.8.3-018
    Affected: 12.5.1-011
    Affected: 11.8.4-004
    Affected: 12.5.2-007
    Affected: 12.5.2-011
    Affected: 14.5.0-498
    Affected: 12.5.4-005
    Affected: 12.5.4-011
    Affected: 12.0.5-011
    Affected: 14.0.3-014
    Affected: 12.5.5-004
    Affected: 12.5.5-005
    Affected: 12.5.5-008
    Affected: 14.0.4-005
    Affected: 14.5.1-008
    Affected: 14.5.1-016
    Affected: 15.0.0-355
    Affected: 15.0.0-322
    Affected: 12.5.6-008
    Affected: 15.1.0-287
    Affected: 14.5.2-011
    Affected: 15.2.0-116
    Affected: 14.0.5-007
    Affected: 15.2.0-164
    Affected: 14.5.1-510
    Affected: 12.0.2-012
    Affected: 12.0.2-004
    Affected: 14.5.1-607
    Affected: 14.5.3-033
    Affected: 12.0.1-334
    Affected: 14.0.1-503
    Affected: 14.0.1-053
    Affected: 11.8.0-429
    Affected: 14.0.1-040
    Affected: 14.0.1-014
    Affected: 12.5.1-043
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-20207",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-02-05T16:57:37.294661Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-02-05T16:57:53.809Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "Cisco Secure Email",
              "vendor": "Cisco",
              "versions": [
                {
                  "status": "affected",
                  "version": "14.0.0-698"
                },
                {
                  "status": "affected",
                  "version": "13.5.1-277"
                },
                {
                  "status": "affected",
                  "version": "13.0.0-392"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-620"
                },
                {
                  "status": "affected",
                  "version": "13.0.5-007"
                },
                {
                  "status": "affected",
                  "version": "13.5.4-038"
                },
                {
                  "status": "affected",
                  "version": "14.2.1-020"
                },
                {
                  "status": "affected",
                  "version": "14.3.0-032"
                },
                {
                  "status": "affected",
                  "version": "15.0.0-104"
                },
                {
                  "status": "affected",
                  "version": "15.0.1-030"
                },
                {
                  "status": "affected",
                  "version": "15.5.0-048"
                },
                {
                  "status": "affected",
                  "version": "15.5.1-055"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "Cisco Secure Email and Web Manager",
              "vendor": "Cisco",
              "versions": [
                {
                  "status": "affected",
                  "version": "13.6.2-023"
                },
                {
                  "status": "affected",
                  "version": "13.6.2-078"
                },
                {
                  "status": "affected",
                  "version": "13.0.0-249"
                },
                {
                  "status": "affected",
                  "version": "13.0.0-277"
                },
                {
                  "status": "affected",
                  "version": "13.8.1-052"
                },
                {
                  "status": "affected",
                  "version": "13.8.1-068"
                },
                {
                  "status": "affected",
                  "version": "13.8.1-074"
                },
                {
                  "status": "affected",
                  "version": "14.0.0-404"
                },
                {
                  "status": "affected",
                  "version": "12.8.1-002"
                },
                {
                  "status": "affected",
                  "version": "14.1.0-227"
                },
                {
                  "status": "affected",
                  "version": "13.6.1-201"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-203"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-212"
                },
                {
                  "status": "affected",
                  "version": "12.8.1-021"
                },
                {
                  "status": "affected",
                  "version": "13.8.1-108"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-224"
                },
                {
                  "status": "affected",
                  "version": "14.3.0-120"
                },
                {
                  "status": "affected",
                  "version": "15.0.0-334"
                },
                {
                  "status": "affected",
                  "version": "15.5.1-024"
                },
                {
                  "status": "affected",
                  "version": "15.5.1-029"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "Cisco Secure Web Appliance",
              "vendor": "Cisco",
              "versions": [
                {
                  "status": "affected",
                  "version": "11.8.0-453"
                },
                {
                  "status": "affected",
                  "version": "12.5.3-002"
                },
                {
                  "status": "affected",
                  "version": "12.0.3-007"
                },
                {
                  "status": "affected",
                  "version": "12.0.3-005"
                },
                {
                  "status": "affected",
                  "version": "14.1.0-032"
                },
                {
                  "status": "affected",
                  "version": "14.1.0-047"
                },
                {
                  "status": "affected",
                  "version": "14.1.0-041"
                },
                {
                  "status": "affected",
                  "version": "12.0.4-002"
                },
                {
                  "status": "affected",
                  "version": "14.0.2-012"
                },
                {
                  "status": "affected",
                  "version": "11.8.0-414"
                },
                {
                  "status": "affected",
                  "version": "12.0.1-268"
                },
                {
                  "status": "affected",
                  "version": "11.8.1-023"
                },
                {
                  "status": "affected",
                  "version": "11.8.3-021"
                },
                {
                  "status": "affected",
                  "version": "11.8.3-018"
                },
                {
                  "status": "affected",
                  "version": "12.5.1-011"
                },
                {
                  "status": "affected",
                  "version": "11.8.4-004"
                },
                {
                  "status": "affected",
                  "version": "12.5.2-007"
                },
                {
                  "status": "affected",
                  "version": "12.5.2-011"
                },
                {
                  "status": "affected",
                  "version": "14.5.0-498"
                },
                {
                  "status": "affected",
                  "version": "12.5.4-005"
                },
                {
                  "status": "affected",
                  "version": "12.5.4-011"
                },
                {
                  "status": "affected",
                  "version": "12.0.5-011"
                },
                {
                  "status": "affected",
                  "version": "14.0.3-014"
                },
                {
                  "status": "affected",
                  "version": "12.5.5-004"
                },
                {
                  "status": "affected",
                  "version": "12.5.5-005"
                },
                {
                  "status": "affected",
                  "version": "12.5.5-008"
                },
                {
                  "status": "affected",
                  "version": "14.0.4-005"
                },
                {
                  "status": "affected",
                  "version": "14.5.1-008"
                },
                {
                  "status": "affected",
                  "version": "14.5.1-016"
                },
                {
                  "status": "affected",
                  "version": "15.0.0-355"
                },
                {
                  "status": "affected",
                  "version": "15.0.0-322"
                },
                {
                  "status": "affected",
                  "version": "12.5.6-008"
                },
                {
                  "status": "affected",
                  "version": "15.1.0-287"
                },
                {
                  "status": "affected",
                  "version": "14.5.2-011"
                },
                {
                  "status": "affected",
                  "version": "15.2.0-116"
                },
                {
                  "status": "affected",
                  "version": "14.0.5-007"
                },
                {
                  "status": "affected",
                  "version": "15.2.0-164"
                },
                {
                  "status": "affected",
                  "version": "14.5.1-510"
                },
                {
                  "status": "affected",
                  "version": "12.0.2-012"
                },
                {
                  "status": "affected",
                  "version": "12.0.2-004"
                },
                {
                  "status": "affected",
                  "version": "14.5.1-607"
                },
                {
                  "status": "affected",
                  "version": "14.5.3-033"
                },
                {
                  "status": "affected",
                  "version": "12.0.1-334"
                },
                {
                  "status": "affected",
                  "version": "14.0.1-503"
                },
                {
                  "status": "affected",
                  "version": "14.0.1-053"
                },
                {
                  "status": "affected",
                  "version": "11.8.0-429"
                },
                {
                  "status": "affected",
                  "version": "14.0.1-040"
                },
                {
                  "status": "affected",
                  "version": "14.0.1-014"
                },
                {
                  "status": "affected",
                  "version": "12.5.1-043"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability in Simple Network Management Protocol (SNMP) polling for Cisco Secure Email and Web Manager, Cisco Secure Email Gateway, and Cisco Secure Web Appliance could allow an authenticated, remote attacker to obtain confidential information about the underlying operating system.\r\n\r\nThis vulnerability exists because the appliances do not protect confidential information at rest in response to SNMP poll requests. An attacker could exploit this vulnerability by sending a crafted SNMP poll request to the affected appliance. A successful exploit could allow the attacker to discover confidential information that should be restricted. To exploit this vulnerability, an attacker must have the configured SNMP credentials."
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "value": "The Cisco PSIRT is not aware of any public announcements or malicious use of the vulnerability that is described in this advisory."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
                "version": "3.1"
              },
              "format": "cvssV3_1"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-200",
                  "description": "Exposure of Sensitive Information to an Unauthorized Actor",
                  "lang": "en",
                  "type": "cwe"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-02-05T16:15:06.012Z",
            "orgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
            "shortName": "cisco"
          },
          "references": [
            {
              "name": "cisco-sa-esa-sma-wsa-snmp-inf-FqPvL8sX",
              "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-sma-wsa-snmp-inf-FqPvL8sX"
            }
          ],
          "source": {
            "advisory": "cisco-sa-esa-sma-wsa-snmp-inf-FqPvL8sX",
            "defects": [
              "CSCwk60819"
            ],
            "discovery": "INTERNAL"
          },
          "title": "Cisco Secure Email Gateway, Cisco Secure Email and Web Appliance and Cisco Secure Web Appliance SNMP Polling Information Disclosure Vulnerability"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
        "assignerShortName": "cisco",
        "cveId": "CVE-2025-20207",
        "datePublished": "2025-02-05T16:15:06.012Z",
        "dateReserved": "2024-10-10T19:15:13.230Z",
        "dateUpdated": "2025-02-05T16:57:53.809Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2025-20185 (GCVE-0-2025-20185)

    Vulnerability from cvelistv5 – Published: 2025-02-05 16:14 – Updated: 2025-02-05 16:59
    VLAI
    Title
    Cisco Secure Email and Web Manager, Secure Email Gateway, and Secure Web Appliance Privilege Escalation Vulnerability
    Summary
    A vulnerability in the implementation of the remote access functionality of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, Cisco Secure Email Gateway, and Cisco Secure Web Appliance could allow an authenticated, local attacker to elevate privileges to root. The attacker must authenticate with valid administrator credentials. This vulnerability is due to an architectural flaw in the password generation algorithm for the remote access functionality. An attacker could exploit this vulnerability by generating a temporary password for the service account. A successful exploit could allow the attacker to execute arbitrary commands as root and access the underlying operating system. Note: The Security Impact Rating (SIR) for this vulnerability is Medium due to the unrestricted scope of information that is accessible to an attacker.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-02-05 16:59 UTC
    CWE
    • CWE-250 - Execution with Unnecessary Privileges
    Impacted products
    Vendor Product Version
    Cisco Cisco Secure Email Affected: 14.0.0-698
    Affected: 13.5.1-277
    Affected: 13.0.0-392
    Affected: 14.2.0-620
    Affected: 13.0.5-007
    Affected: 13.5.4-038
    Affected: 14.2.1-020
    Affected: 14.3.0-032
    Affected: 15.0.0-104
    Affected: 15.0.1-030
    Affected: 15.5.0-048
    Affected: 15.5.1-055
    Affected: 15.5.2-018
    Affected: 15.0.3-002
    Create a notification for this product.
    Cisco Cisco Secure Email and Web Manager Affected: 13.6.2-023
    Affected: 13.6.2-078
    Affected: 13.0.0-249
    Affected: 13.0.0-277
    Affected: 13.8.1-052
    Affected: 13.8.1-068
    Affected: 13.8.1-074
    Affected: 14.0.0-404
    Affected: 12.8.1-002
    Affected: 14.1.0-227
    Affected: 13.6.1-201
    Affected: 14.2.0-203
    Affected: 14.2.0-212
    Affected: 12.8.1-021
    Affected: 13.8.1-108
    Affected: 14.2.0-224
    Affected: 14.3.0-120
    Affected: 15.0.0-334
    Affected: 15.5.1-024
    Affected: 15.5.1-029
    Affected: 15.5.2-005
    Create a notification for this product.
    Cisco Cisco Secure Web Appliance Affected: 11.8.0-453
    Affected: 12.5.3-002
    Affected: 12.0.3-007
    Affected: 12.0.3-005
    Affected: 14.1.0-032
    Affected: 14.1.0-047
    Affected: 14.1.0-041
    Affected: 12.0.4-002
    Affected: 14.0.2-012
    Affected: 11.8.0-414
    Affected: 12.0.1-268
    Affected: 11.8.1-023
    Affected: 11.8.3-021
    Affected: 11.8.3-018
    Affected: 12.5.1-011
    Affected: 11.8.4-004
    Affected: 12.5.2-007
    Affected: 12.5.2-011
    Affected: 14.5.0-498
    Affected: 12.5.4-005
    Affected: 12.5.4-011
    Affected: 12.0.5-011
    Affected: 14.0.3-014
    Affected: 12.5.5-004
    Affected: 12.5.5-005
    Affected: 12.5.5-008
    Affected: 14.0.4-005
    Affected: 14.5.1-008
    Affected: 14.5.1-016
    Affected: 15.0.0-355
    Affected: 15.0.0-322
    Affected: 12.5.6-008
    Affected: 15.1.0-287
    Affected: 14.5.2-011
    Affected: 15.2.0-116
    Affected: 14.0.5-007
    Affected: 15.2.0-164
    Affected: 14.5.1-510
    Affected: 12.0.2-012
    Affected: 12.0.2-004
    Affected: 14.5.1-607
    Affected: 14.5.3-033
    Affected: 15.0.1-004
    Affected: 15.2.1-011
    Affected: 14.5.0-673
    Affected: 14.5.0-537
    Affected: 12.0.1-334
    Affected: 14.0.1-503
    Affected: 14.0.1-053
    Affected: 11.8.0-429
    Affected: 14.0.1-040
    Affected: 14.0.1-014
    Affected: 12.5.1-043
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-20185",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-02-05T16:59:20.922545Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-02-05T16:59:47.445Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "Cisco Secure Email",
              "vendor": "Cisco",
              "versions": [
                {
                  "status": "affected",
                  "version": "14.0.0-698"
                },
                {
                  "status": "affected",
                  "version": "13.5.1-277"
                },
                {
                  "status": "affected",
                  "version": "13.0.0-392"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-620"
                },
                {
                  "status": "affected",
                  "version": "13.0.5-007"
                },
                {
                  "status": "affected",
                  "version": "13.5.4-038"
                },
                {
                  "status": "affected",
                  "version": "14.2.1-020"
                },
                {
                  "status": "affected",
                  "version": "14.3.0-032"
                },
                {
                  "status": "affected",
                  "version": "15.0.0-104"
                },
                {
                  "status": "affected",
                  "version": "15.0.1-030"
                },
                {
                  "status": "affected",
                  "version": "15.5.0-048"
                },
                {
                  "status": "affected",
                  "version": "15.5.1-055"
                },
                {
                  "status": "affected",
                  "version": "15.5.2-018"
                },
                {
                  "status": "affected",
                  "version": "15.0.3-002"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "Cisco Secure Email and Web Manager",
              "vendor": "Cisco",
              "versions": [
                {
                  "status": "affected",
                  "version": "13.6.2-023"
                },
                {
                  "status": "affected",
                  "version": "13.6.2-078"
                },
                {
                  "status": "affected",
                  "version": "13.0.0-249"
                },
                {
                  "status": "affected",
                  "version": "13.0.0-277"
                },
                {
                  "status": "affected",
                  "version": "13.8.1-052"
                },
                {
                  "status": "affected",
                  "version": "13.8.1-068"
                },
                {
                  "status": "affected",
                  "version": "13.8.1-074"
                },
                {
                  "status": "affected",
                  "version": "14.0.0-404"
                },
                {
                  "status": "affected",
                  "version": "12.8.1-002"
                },
                {
                  "status": "affected",
                  "version": "14.1.0-227"
                },
                {
                  "status": "affected",
                  "version": "13.6.1-201"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-203"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-212"
                },
                {
                  "status": "affected",
                  "version": "12.8.1-021"
                },
                {
                  "status": "affected",
                  "version": "13.8.1-108"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-224"
                },
                {
                  "status": "affected",
                  "version": "14.3.0-120"
                },
                {
                  "status": "affected",
                  "version": "15.0.0-334"
                },
                {
                  "status": "affected",
                  "version": "15.5.1-024"
                },
                {
                  "status": "affected",
                  "version": "15.5.1-029"
                },
                {
                  "status": "affected",
                  "version": "15.5.2-005"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "Cisco Secure Web Appliance",
              "vendor": "Cisco",
              "versions": [
                {
                  "status": "affected",
                  "version": "11.8.0-453"
                },
                {
                  "status": "affected",
                  "version": "12.5.3-002"
                },
                {
                  "status": "affected",
                  "version": "12.0.3-007"
                },
                {
                  "status": "affected",
                  "version": "12.0.3-005"
                },
                {
                  "status": "affected",
                  "version": "14.1.0-032"
                },
                {
                  "status": "affected",
                  "version": "14.1.0-047"
                },
                {
                  "status": "affected",
                  "version": "14.1.0-041"
                },
                {
                  "status": "affected",
                  "version": "12.0.4-002"
                },
                {
                  "status": "affected",
                  "version": "14.0.2-012"
                },
                {
                  "status": "affected",
                  "version": "11.8.0-414"
                },
                {
                  "status": "affected",
                  "version": "12.0.1-268"
                },
                {
                  "status": "affected",
                  "version": "11.8.1-023"
                },
                {
                  "status": "affected",
                  "version": "11.8.3-021"
                },
                {
                  "status": "affected",
                  "version": "11.8.3-018"
                },
                {
                  "status": "affected",
                  "version": "12.5.1-011"
                },
                {
                  "status": "affected",
                  "version": "11.8.4-004"
                },
                {
                  "status": "affected",
                  "version": "12.5.2-007"
                },
                {
                  "status": "affected",
                  "version": "12.5.2-011"
                },
                {
                  "status": "affected",
                  "version": "14.5.0-498"
                },
                {
                  "status": "affected",
                  "version": "12.5.4-005"
                },
                {
                  "status": "affected",
                  "version": "12.5.4-011"
                },
                {
                  "status": "affected",
                  "version": "12.0.5-011"
                },
                {
                  "status": "affected",
                  "version": "14.0.3-014"
                },
                {
                  "status": "affected",
                  "version": "12.5.5-004"
                },
                {
                  "status": "affected",
                  "version": "12.5.5-005"
                },
                {
                  "status": "affected",
                  "version": "12.5.5-008"
                },
                {
                  "status": "affected",
                  "version": "14.0.4-005"
                },
                {
                  "status": "affected",
                  "version": "14.5.1-008"
                },
                {
                  "status": "affected",
                  "version": "14.5.1-016"
                },
                {
                  "status": "affected",
                  "version": "15.0.0-355"
                },
                {
                  "status": "affected",
                  "version": "15.0.0-322"
                },
                {
                  "status": "affected",
                  "version": "12.5.6-008"
                },
                {
                  "status": "affected",
                  "version": "15.1.0-287"
                },
                {
                  "status": "affected",
                  "version": "14.5.2-011"
                },
                {
                  "status": "affected",
                  "version": "15.2.0-116"
                },
                {
                  "status": "affected",
                  "version": "14.0.5-007"
                },
                {
                  "status": "affected",
                  "version": "15.2.0-164"
                },
                {
                  "status": "affected",
                  "version": "14.5.1-510"
                },
                {
                  "status": "affected",
                  "version": "12.0.2-012"
                },
                {
                  "status": "affected",
                  "version": "12.0.2-004"
                },
                {
                  "status": "affected",
                  "version": "14.5.1-607"
                },
                {
                  "status": "affected",
                  "version": "14.5.3-033"
                },
                {
                  "status": "affected",
                  "version": "15.0.1-004"
                },
                {
                  "status": "affected",
                  "version": "15.2.1-011"
                },
                {
                  "status": "affected",
                  "version": "14.5.0-673"
                },
                {
                  "status": "affected",
                  "version": "14.5.0-537"
                },
                {
                  "status": "affected",
                  "version": "12.0.1-334"
                },
                {
                  "status": "affected",
                  "version": "14.0.1-503"
                },
                {
                  "status": "affected",
                  "version": "14.0.1-053"
                },
                {
                  "status": "affected",
                  "version": "11.8.0-429"
                },
                {
                  "status": "affected",
                  "version": "14.0.1-040"
                },
                {
                  "status": "affected",
                  "version": "14.0.1-014"
                },
                {
                  "status": "affected",
                  "version": "12.5.1-043"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability in the implementation of the remote access functionality of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, Cisco Secure Email Gateway, and Cisco Secure Web Appliance could allow an authenticated, local attacker to elevate privileges to root. The attacker must authenticate with valid administrator credentials.\r\n\r\nThis vulnerability is due to an architectural flaw in the password generation algorithm for the remote access functionality. An attacker could exploit this vulnerability by generating a temporary password for the service account. A successful exploit could allow the attacker to execute arbitrary commands as root and access the underlying operating system.\r\nNote: The Security Impact Rating (SIR) for this vulnerability is Medium due to the unrestricted scope of information that is accessible to an attacker."
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "value": "The Cisco PSIRT is not aware of any public announcements or malicious use of the vulnerabilities that are described in this advisory."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "NONE",
                "baseScore": 3.4,
                "baseSeverity": "LOW",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N",
                "version": "3.1"
              },
              "format": "cvssV3_1"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-250",
                  "description": "Execution with Unnecessary Privileges",
                  "lang": "en",
                  "type": "cwe"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-02-05T16:14:38.541Z",
            "orgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
            "shortName": "cisco"
          },
          "references": [
            {
              "name": "cisco-sa-esa-sma-wsa-multi-yKUJhS34",
              "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-sma-wsa-multi-yKUJhS34"
            }
          ],
          "source": {
            "advisory": "cisco-sa-esa-sma-wsa-multi-yKUJhS34",
            "defects": [
              "CSCwk70576"
            ],
            "discovery": "EXTERNAL"
          },
          "title": "Cisco Secure Email and Web Manager, Secure Email Gateway, and Secure Web Appliance Privilege Escalation Vulnerability"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
        "assignerShortName": "cisco",
        "cveId": "CVE-2025-20185",
        "datePublished": "2025-02-05T16:14:38.541Z",
        "dateReserved": "2024-10-10T19:15:13.226Z",
        "dateUpdated": "2025-02-05T16:59:47.445Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2025-20184 (GCVE-0-2025-20184)

    Vulnerability from cvelistv5 – Published: 2025-02-05 16:14 – Updated: 2025-02-05 17:00
    VLAI
    Title
    Cisco Secure Email and Web Manager and Secure Web Appliance Command Injection Vulnerability
    Summary
    A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Web Appliance could allow an authenticated, remote attacker to perform command injection attacks against an affected device. The attacker must authenticate with valid administrator credentials. This vulnerability is due to insufficient validation of XML configuration files by an affected device. An attacker could exploit this vulnerability by uploading a crafted XML configuration file. A successful exploit could allow the attacker to inject commands to the underlying operating system with root privileges.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-02-05 16:59 UTC
    CWE
    • CWE-20 - Improper Input Validation
    Impacted products
    Vendor Product Version
    Cisco Cisco Secure Email Affected: 14.0.0-698
    Affected: 13.5.1-277
    Affected: 13.0.0-392
    Affected: 14.2.0-620
    Affected: 13.0.5-007
    Affected: 13.5.4-038
    Affected: 14.2.1-020
    Affected: 14.3.0-032
    Affected: 15.0.0-104
    Affected: 15.0.1-030
    Affected: 15.5.0-048
    Affected: 15.5.1-055
    Affected: 15.5.2-018
    Affected: 15.0.3-002
    Affected: 15.5.3-022
    Create a notification for this product.
    Cisco Cisco Secure Web Appliance Affected: 11.8.0-453
    Affected: 12.5.3-002
    Affected: 12.0.3-007
    Affected: 12.0.3-005
    Affected: 14.1.0-032
    Affected: 14.1.0-047
    Affected: 14.1.0-041
    Affected: 12.0.4-002
    Affected: 14.0.2-012
    Affected: 11.8.0-414
    Affected: 12.0.1-268
    Affected: 11.8.1-023
    Affected: 11.8.3-021
    Affected: 11.8.3-018
    Affected: 12.5.1-011
    Affected: 11.8.4-004
    Affected: 12.5.2-007
    Affected: 12.5.2-011
    Affected: 14.5.0-498
    Affected: 12.5.4-005
    Affected: 12.5.4-011
    Affected: 12.0.5-011
    Affected: 14.0.3-014
    Affected: 12.5.5-004
    Affected: 12.5.5-005
    Affected: 12.5.5-008
    Affected: 14.0.4-005
    Affected: 14.5.1-008
    Affected: 14.5.1-016
    Affected: 15.0.0-355
    Affected: 15.0.0-322
    Affected: 12.5.6-008
    Affected: 15.1.0-287
    Affected: 14.5.2-011
    Affected: 15.2.0-116
    Affected: 14.0.5-007
    Affected: 15.2.0-164
    Affected: 14.5.1-510
    Affected: 12.0.2-012
    Affected: 12.0.2-004
    Affected: 14.5.1-607
    Affected: 14.5.3-033
    Affected: 15.0.1-004
    Affected: 15.2.1-011
    Affected: 14.5.0-673
    Affected: 14.5.0-537
    Affected: 12.0.1-334
    Affected: 14.0.1-503
    Affected: 14.0.1-053
    Affected: 11.8.0-429
    Affected: 14.0.1-040
    Affected: 14.0.1-014
    Affected: 12.5.1-043
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-20184",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-02-05T16:59:57.945223Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-02-05T17:00:15.021Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "Cisco Secure Email",
              "vendor": "Cisco",
              "versions": [
                {
                  "status": "affected",
                  "version": "14.0.0-698"
                },
                {
                  "status": "affected",
                  "version": "13.5.1-277"
                },
                {
                  "status": "affected",
                  "version": "13.0.0-392"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-620"
                },
                {
                  "status": "affected",
                  "version": "13.0.5-007"
                },
                {
                  "status": "affected",
                  "version": "13.5.4-038"
                },
                {
                  "status": "affected",
                  "version": "14.2.1-020"
                },
                {
                  "status": "affected",
                  "version": "14.3.0-032"
                },
                {
                  "status": "affected",
                  "version": "15.0.0-104"
                },
                {
                  "status": "affected",
                  "version": "15.0.1-030"
                },
                {
                  "status": "affected",
                  "version": "15.5.0-048"
                },
                {
                  "status": "affected",
                  "version": "15.5.1-055"
                },
                {
                  "status": "affected",
                  "version": "15.5.2-018"
                },
                {
                  "status": "affected",
                  "version": "15.0.3-002"
                },
                {
                  "status": "affected",
                  "version": "15.5.3-022"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "Cisco Secure Web Appliance",
              "vendor": "Cisco",
              "versions": [
                {
                  "status": "affected",
                  "version": "11.8.0-453"
                },
                {
                  "status": "affected",
                  "version": "12.5.3-002"
                },
                {
                  "status": "affected",
                  "version": "12.0.3-007"
                },
                {
                  "status": "affected",
                  "version": "12.0.3-005"
                },
                {
                  "status": "affected",
                  "version": "14.1.0-032"
                },
                {
                  "status": "affected",
                  "version": "14.1.0-047"
                },
                {
                  "status": "affected",
                  "version": "14.1.0-041"
                },
                {
                  "status": "affected",
                  "version": "12.0.4-002"
                },
                {
                  "status": "affected",
                  "version": "14.0.2-012"
                },
                {
                  "status": "affected",
                  "version": "11.8.0-414"
                },
                {
                  "status": "affected",
                  "version": "12.0.1-268"
                },
                {
                  "status": "affected",
                  "version": "11.8.1-023"
                },
                {
                  "status": "affected",
                  "version": "11.8.3-021"
                },
                {
                  "status": "affected",
                  "version": "11.8.3-018"
                },
                {
                  "status": "affected",
                  "version": "12.5.1-011"
                },
                {
                  "status": "affected",
                  "version": "11.8.4-004"
                },
                {
                  "status": "affected",
                  "version": "12.5.2-007"
                },
                {
                  "status": "affected",
                  "version": "12.5.2-011"
                },
                {
                  "status": "affected",
                  "version": "14.5.0-498"
                },
                {
                  "status": "affected",
                  "version": "12.5.4-005"
                },
                {
                  "status": "affected",
                  "version": "12.5.4-011"
                },
                {
                  "status": "affected",
                  "version": "12.0.5-011"
                },
                {
                  "status": "affected",
                  "version": "14.0.3-014"
                },
                {
                  "status": "affected",
                  "version": "12.5.5-004"
                },
                {
                  "status": "affected",
                  "version": "12.5.5-005"
                },
                {
                  "status": "affected",
                  "version": "12.5.5-008"
                },
                {
                  "status": "affected",
                  "version": "14.0.4-005"
                },
                {
                  "status": "affected",
                  "version": "14.5.1-008"
                },
                {
                  "status": "affected",
                  "version": "14.5.1-016"
                },
                {
                  "status": "affected",
                  "version": "15.0.0-355"
                },
                {
                  "status": "affected",
                  "version": "15.0.0-322"
                },
                {
                  "status": "affected",
                  "version": "12.5.6-008"
                },
                {
                  "status": "affected",
                  "version": "15.1.0-287"
                },
                {
                  "status": "affected",
                  "version": "14.5.2-011"
                },
                {
                  "status": "affected",
                  "version": "15.2.0-116"
                },
                {
                  "status": "affected",
                  "version": "14.0.5-007"
                },
                {
                  "status": "affected",
                  "version": "15.2.0-164"
                },
                {
                  "status": "affected",
                  "version": "14.5.1-510"
                },
                {
                  "status": "affected",
                  "version": "12.0.2-012"
                },
                {
                  "status": "affected",
                  "version": "12.0.2-004"
                },
                {
                  "status": "affected",
                  "version": "14.5.1-607"
                },
                {
                  "status": "affected",
                  "version": "14.5.3-033"
                },
                {
                  "status": "affected",
                  "version": "15.0.1-004"
                },
                {
                  "status": "affected",
                  "version": "15.2.1-011"
                },
                {
                  "status": "affected",
                  "version": "14.5.0-673"
                },
                {
                  "status": "affected",
                  "version": "14.5.0-537"
                },
                {
                  "status": "affected",
                  "version": "12.0.1-334"
                },
                {
                  "status": "affected",
                  "version": "14.0.1-503"
                },
                {
                  "status": "affected",
                  "version": "14.0.1-053"
                },
                {
                  "status": "affected",
                  "version": "11.8.0-429"
                },
                {
                  "status": "affected",
                  "version": "14.0.1-040"
                },
                {
                  "status": "affected",
                  "version": "14.0.1-014"
                },
                {
                  "status": "affected",
                  "version": "12.5.1-043"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Web Appliance could allow an authenticated, remote attacker to perform command injection attacks against an affected device. The attacker must authenticate with valid administrator credentials.\r\n\r\nThis vulnerability is due to insufficient validation of XML configuration files by an affected device. An attacker could exploit this vulnerability by uploading a crafted XML configuration file. A successful exploit could allow the attacker to inject commands to the underlying operating system with root privileges."
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "value": "The Cisco PSIRT is not aware of any public announcements or malicious use of the vulnerabilities that are described in this advisory."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N",
                "version": "3.1"
              },
              "format": "cvssV3_1"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-20",
                  "description": "Improper Input Validation",
                  "lang": "en",
                  "type": "cwe"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-02-05T16:14:30.863Z",
            "orgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
            "shortName": "cisco"
          },
          "references": [
            {
              "name": "cisco-sa-esa-sma-wsa-multi-yKUJhS34",
              "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-sma-wsa-multi-yKUJhS34"
            }
          ],
          "source": {
            "advisory": "cisco-sa-esa-sma-wsa-multi-yKUJhS34",
            "defects": [
              "CSCwk70559"
            ],
            "discovery": "EXTERNAL"
          },
          "title": "Cisco Secure Email and Web Manager and Secure Web Appliance Command Injection Vulnerability"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
        "assignerShortName": "cisco",
        "cveId": "CVE-2025-20184",
        "datePublished": "2025-02-05T16:14:30.863Z",
        "dateReserved": "2024-10-10T19:15:13.225Z",
        "dateUpdated": "2025-02-05T17:00:15.021Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2025-20180 (GCVE-0-2025-20180)

    Vulnerability from cvelistv5 – Published: 2025-02-05 16:14 – Updated: 2025-02-05 17:20
    VLAI
    Title
    Cisco Secure Email and Web Manager and Secure Email Gateway Cross-Site Scripting Vulnerability
    Summary
    A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Email Gateway could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker must have valid credentials for a user account with at least the role of Operator.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-02-05 17:20 UTC
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    Impacted products
    Vendor Product Version
    Cisco Cisco Secure Email Affected: 14.0.0-698
    Affected: 13.5.1-277
    Affected: 13.0.0-392
    Affected: 14.2.0-620
    Affected: 13.0.5-007
    Affected: 13.5.4-038
    Affected: 14.2.1-020
    Affected: 14.3.0-032
    Affected: 15.0.0-104
    Affected: 15.0.1-030
    Affected: 15.5.0-048
    Affected: 15.5.1-055
    Affected: 15.5.2-018
    Affected: 16.0.0-050
    Affected: 15.0.3-002
    Affected: 16.0.0-054
    Create a notification for this product.
    Cisco Cisco Secure Email and Web Manager Affected: 13.6.2-023
    Affected: 13.6.2-078
    Affected: 13.0.0-249
    Affected: 13.0.0-277
    Affected: 13.8.1-052
    Affected: 13.8.1-068
    Affected: 13.8.1-074
    Affected: 14.0.0-404
    Affected: 12.8.1-002
    Affected: 14.1.0-227
    Affected: 13.6.1-201
    Affected: 14.2.0-203
    Affected: 14.2.0-212
    Affected: 12.8.1-021
    Affected: 13.8.1-108
    Affected: 14.2.0-224
    Affected: 14.3.0-120
    Affected: 15.0.0-334
    Affected: 15.5.1-024
    Affected: 15.5.1-029
    Affected: 15.5.2-005
    Affected: 16.0.0-195
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-20180",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-02-05T17:20:31.169165Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-02-05T17:20:45.616Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "Cisco Secure Email",
              "vendor": "Cisco",
              "versions": [
                {
                  "status": "affected",
                  "version": "14.0.0-698"
                },
                {
                  "status": "affected",
                  "version": "13.5.1-277"
                },
                {
                  "status": "affected",
                  "version": "13.0.0-392"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-620"
                },
                {
                  "status": "affected",
                  "version": "13.0.5-007"
                },
                {
                  "status": "affected",
                  "version": "13.5.4-038"
                },
                {
                  "status": "affected",
                  "version": "14.2.1-020"
                },
                {
                  "status": "affected",
                  "version": "14.3.0-032"
                },
                {
                  "status": "affected",
                  "version": "15.0.0-104"
                },
                {
                  "status": "affected",
                  "version": "15.0.1-030"
                },
                {
                  "status": "affected",
                  "version": "15.5.0-048"
                },
                {
                  "status": "affected",
                  "version": "15.5.1-055"
                },
                {
                  "status": "affected",
                  "version": "15.5.2-018"
                },
                {
                  "status": "affected",
                  "version": "16.0.0-050"
                },
                {
                  "status": "affected",
                  "version": "15.0.3-002"
                },
                {
                  "status": "affected",
                  "version": "16.0.0-054"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "Cisco Secure Email and Web Manager",
              "vendor": "Cisco",
              "versions": [
                {
                  "status": "affected",
                  "version": "13.6.2-023"
                },
                {
                  "status": "affected",
                  "version": "13.6.2-078"
                },
                {
                  "status": "affected",
                  "version": "13.0.0-249"
                },
                {
                  "status": "affected",
                  "version": "13.0.0-277"
                },
                {
                  "status": "affected",
                  "version": "13.8.1-052"
                },
                {
                  "status": "affected",
                  "version": "13.8.1-068"
                },
                {
                  "status": "affected",
                  "version": "13.8.1-074"
                },
                {
                  "status": "affected",
                  "version": "14.0.0-404"
                },
                {
                  "status": "affected",
                  "version": "12.8.1-002"
                },
                {
                  "status": "affected",
                  "version": "14.1.0-227"
                },
                {
                  "status": "affected",
                  "version": "13.6.1-201"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-203"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-212"
                },
                {
                  "status": "affected",
                  "version": "12.8.1-021"
                },
                {
                  "status": "affected",
                  "version": "13.8.1-108"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-224"
                },
                {
                  "status": "affected",
                  "version": "14.3.0-120"
                },
                {
                  "status": "affected",
                  "version": "15.0.0-334"
                },
                {
                  "status": "affected",
                  "version": "15.5.1-024"
                },
                {
                  "status": "affected",
                  "version": "15.5.1-029"
                },
                {
                  "status": "affected",
                  "version": "15.5.2-005"
                },
                {
                  "status": "affected",
                  "version": "16.0.0-195"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Email Gateway could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface.\r\n\r\nThis vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker must have valid credentials for a user account with at least the role of Operator."
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "value": "The Cisco PSIRT is not aware of any public announcements or malicious use of the vulnerability that is described in this advisory."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 4.8,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "HIGH",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N",
                "version": "3.1"
              },
              "format": "cvssV3_1"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "cwe"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-02-05T16:14:11.746Z",
            "orgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
            "shortName": "cisco"
          },
          "references": [
            {
              "name": "cisco-sa-esa-sma-xss-WCk2WcuG",
              "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-sma-xss-WCk2WcuG"
            }
          ],
          "source": {
            "advisory": "cisco-sa-esa-sma-xss-WCk2WcuG",
            "defects": [
              "CSCwn25954"
            ],
            "discovery": "INTERNAL"
          },
          "title": "Cisco Secure Email and Web Manager and Secure Email Gateway Cross-Site Scripting Vulnerability"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
        "assignerShortName": "cisco",
        "cveId": "CVE-2025-20180",
        "datePublished": "2025-02-05T16:14:11.746Z",
        "dateReserved": "2024-10-10T19:15:13.225Z",
        "dateUpdated": "2025-02-05T17:20:45.616Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2020-3548 (GCVE-0-2020-3548)

    Vulnerability from cvelistv5 – Published: 2024-11-18 15:53 – Updated: 2024-11-18 16:32
    VLAI
    Title
    Cisco Email Security Appliance Denial Of Service Vulnerability
    Summary
    A vulnerability in the Transport Layer Security (TLS) protocol implementation of Cisco AsyncOS software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause high CPU usage on an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to inefficient processing of incoming TLS traffic. An attacker could exploit this vulnerability by sending a series of crafted TLS packets to an affected device. A successful exploit could allow the attacker to trigger a prolonged state of high CPU utilization. The affected device would still be operative, but response time and overall performance may be degraded.There are no workarounds that address this vulnerability.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-11-18 16:30 UTC
    CWE
    • CWE-407 - Inefficient Algorithmic Complexity
    Impacted products
    Vendor Product Version
    Cisco Cisco Secure Email Affected: N/A
    Create a notification for this product.
    cisco secure_email Affected: 0 , ≤ 13.5.1-277 (custom)
        cpe:2.3:a:cisco:secure_email:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:cisco:secure_email:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "secure_email",
                "vendor": "cisco",
                "versions": [
                  {
                    "lessThanOrEqual": "13.5.1-277",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2020-3548",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-11-18T16:30:29.514984Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-11-18T16:32:04.999Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Cisco Secure Email",
              "vendor": "Cisco",
              "versions": [
                {
                  "status": "affected",
                  "version": "N/A"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability in the Transport Layer Security (TLS) protocol implementation of Cisco\u0026nbsp;AsyncOS software for Cisco\u0026nbsp;Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause high CPU usage on an affected device, resulting in a denial of service (DoS) condition.\r\nThe vulnerability is due to inefficient processing of incoming TLS traffic. An attacker could exploit this vulnerability by sending a series of crafted TLS packets to an affected device. A successful exploit could allow the attacker to trigger a prolonged state of high CPU utilization. The affected device would still be operative, but response time and overall performance may be degraded.There are no workarounds that address this vulnerability."
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "value": "The Cisco Product Security Incident Response Team (PSIRT) is not aware of any public announcements or malicious use of the vulnerability that is described in this advisory."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/RL:X/RC:X/E:X",
                "version": "3.1"
              },
              "format": "cvssV3_1"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-407",
                  "description": "Inefficient Algorithmic Complexity",
                  "lang": "en",
                  "type": "cwe"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-11-18T15:53:40.744Z",
            "orgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
            "shortName": "cisco"
          },
          "references": [
            {
              "name": "cisco-sa-esa-tls-dos-xW53TBhb",
              "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-tls-dos-xW53TBhb"
            }
          ],
          "source": {
            "advisory": "cisco-sa-esa-tls-dos-xW53TBhb",
            "defects": [
              "CSCvu35999"
            ],
            "discovery": "INTERNAL"
          },
          "title": "Cisco Email Security Appliance Denial Of Service Vulnerability"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
        "assignerShortName": "cisco",
        "cveId": "CVE-2020-3548",
        "datePublished": "2024-11-18T15:53:40.744Z",
        "dateReserved": "2019-12-12T00:00:00.000Z",
        "dateUpdated": "2024-11-18T16:32:04.999Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-20504 (GCVE-0-2024-20504)

    Vulnerability from cvelistv5 – Published: 2024-11-06 16:29 – Updated: 2024-11-06 17:05
    VLAI
    Title
    Cisco Secure Email and Web Manager, Secure Email Gateway, and Secure Web Appliance Stored Cross-Site Scripting Vulnerabilities
    Summary
    A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, Secure Email Gateway, and Secure Web Appliance could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-11-06 17:05 UTC
    CWE
    • CWE-80 - Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
    Impacted products
    Vendor Product Version
    Cisco Cisco Secure Email Affected: 14.0.0-698
    Affected: 14.2.0-620
    Affected: 14.2.1-020
    Affected: 14.3.0-032
    Affected: 15.0.0-104
    Affected: 15.0.1-030
    Affected: 15.5.0-048
    Affected: 15.5.1-055
    Create a notification for this product.
    Cisco Cisco Secure Email and Web Manager Affected: 14.0.0-404
    Affected: 14.1.0-223
    Affected: 14.1.0-227
    Affected: 14.2.0-212
    Affected: 14.2.0-224
    Affected: 14.2.1-020
    Affected: 14.3.0-120
    Affected: 15.0.0-334
    Affected: 15.5.1-024
    Affected: 15.5.1-029
    Create a notification for this product.
    Cisco Cisco Secure Web Appliance Affected: 14.1.0-032
    Affected: 14.1.0-047
    Affected: 14.1.0-041
    Affected: 14.0.2-012
    Affected: 14.5.0-498
    Affected: 14.0.3-014
    Affected: 14.0.4-005
    Affected: 14.5.1-008
    Affected: 14.5.1-016
    Affected: 15.0.0-355
    Affected: 15.0.0-322
    Affected: 15.1.0-287
    Affected: 14.5.2-011
    Affected: 15.2.0-116
    Affected: 14.0.5-007
    Affected: 15.2.0-164
    Affected: 14.5.1-510
    Affected: 14.5.1-607
    Affected: 14.5.3-033
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-20504",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-11-06T17:05:32.372312Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-11-06T17:05:40.097Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "Cisco Secure Email",
              "vendor": "Cisco",
              "versions": [
                {
                  "status": "affected",
                  "version": "14.0.0-698"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-620"
                },
                {
                  "status": "affected",
                  "version": "14.2.1-020"
                },
                {
                  "status": "affected",
                  "version": "14.3.0-032"
                },
                {
                  "status": "affected",
                  "version": "15.0.0-104"
                },
                {
                  "status": "affected",
                  "version": "15.0.1-030"
                },
                {
                  "status": "affected",
                  "version": "15.5.0-048"
                },
                {
                  "status": "affected",
                  "version": "15.5.1-055"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "Cisco Secure Email and Web Manager",
              "vendor": "Cisco",
              "versions": [
                {
                  "status": "affected",
                  "version": "14.0.0-404"
                },
                {
                  "status": "affected",
                  "version": "14.1.0-223"
                },
                {
                  "status": "affected",
                  "version": "14.1.0-227"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-212"
                },
                {
                  "status": "affected",
                  "version": "14.2.0-224"
                },
                {
                  "status": "affected",
                  "version": "14.2.1-020"
                },
                {
                  "status": "affected",
                  "version": "14.3.0-120"
                },
                {
                  "status": "affected",
                  "version": "15.0.0-334"
                },
                {
                  "status": "affected",
                  "version": "15.5.1-024"
                },
                {
                  "status": "affected",
                  "version": "15.5.1-029"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "Cisco Secure Web Appliance",
              "vendor": "Cisco",
              "versions": [
                {
                  "status": "affected",
                  "version": "14.1.0-032"
                },
                {
                  "status": "affected",
                  "version": "14.1.0-047"
                },
                {
                  "status": "affected",
                  "version": "14.1.0-041"
                },
                {
                  "status": "affected",
                  "version": "14.0.2-012"
                },
                {
                  "status": "affected",
                  "version": "14.5.0-498"
                },
                {
                  "status": "affected",
                  "version": "14.0.3-014"
                },
                {
                  "status": "affected",
                  "version": "14.0.4-005"
                },
                {
                  "status": "affected",
                  "version": "14.5.1-008"
                },
                {
                  "status": "affected",
                  "version": "14.5.1-016"
                },
                {
                  "status": "affected",
                  "version": "15.0.0-355"
                },
                {
                  "status": "affected",
                  "version": "15.0.0-322"
                },
                {
                  "status": "affected",
                  "version": "15.1.0-287"
                },
                {
                  "status": "affected",
                  "version": "14.5.2-011"
                },
                {
                  "status": "affected",
                  "version": "15.2.0-116"
                },
                {
                  "status": "affected",
                  "version": "14.0.5-007"
                },
                {
                  "status": "affected",
                  "version": "15.2.0-164"
                },
                {
                  "status": "affected",
                  "version": "14.5.1-510"
                },
                {
                  "status": "affected",
                  "version": "14.5.1-607"
                },
                {
                  "status": "affected",
                  "version": "14.5.3-033"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, Secure Email Gateway, and Secure Web Appliance could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface.\r\n\r\nThis vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information."
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "value": "The Cisco PSIRT is not aware of any public announcements or malicious use of the vulnerability that is described in this advisory."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.4,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
                "version": "3.1"
              },
              "format": "cvssV3_1"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-80",
                  "description": "Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)",
                  "lang": "en",
                  "type": "cwe"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-11-06T16:29:37.791Z",
            "orgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
            "shortName": "cisco"
          },
          "references": [
            {
              "name": "cisco-sa-esa-wsa-sma-xss-zYm3f49n",
              "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-wsa-sma-xss-zYm3f49n"
            }
          ],
          "source": {
            "advisory": "cisco-sa-esa-wsa-sma-xss-zYm3f49n",
            "defects": [
              "CSCwj72814"
            ],
            "discovery": "EXTERNAL"
          },
          "title": "Cisco Secure Email and Web Manager, Secure Email Gateway, and Secure Web Appliance Stored Cross-Site Scripting Vulnerabilities"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
        "assignerShortName": "cisco",
        "cveId": "CVE-2024-20504",
        "datePublished": "2024-11-06T16:29:37.791Z",
        "dateReserved": "2023-11-08T15:08:07.687Z",
        "dateUpdated": "2024-11-06T17:05:40.097Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }