CyberzSOC

Publication detail
← Back to advisories & guidance

2025-042: Critical Vulnerability in Cisco Secure Email and Web Manager ↗ source

December 18, 2025 CERT-EU Advisory

Summary

It is recommended to follow Cisco’s recommendations to check whether vulnerable appliances have been compromised, and to remediate the issue. While there is not much technical details about the vulnerability CVE-2025-20393, with a CVSS score of 10, Cisco reveals that it allows attackers to execute arbitrary commands with root privileges on the underlying operating system of an affected appliance. This vulnerability affects Cisco Secure Email Gateway, both physical and virtual, and Cisco SecureEmailandWebManagerappliances,bothphysicalandvirtual,whenbothofthefollowing It is recommended to check if Cisco Secure Email Gateway and Cisco Secure Email and Web Manager appliances are configured with the Spam Quarantine feature, and if they are, that the feature is not reachable from the internet. If it is the case, it is recommended to open a Cisco Technical Assistance Center (TAC) case to verify whether an appliance has been compromised It is also recommended to follow Cisco’s recommendations to remediate the issue [1]: In case the appliance was found to be compromised, it is recommended to investigate further any lateral movement that may have occurred within the network.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2025-20393 10.0 Critical Cisco Multiple Products Cisco Secure Email Gateway, Secure Email, AsyncOS Software, and Web Manager appliances contains an improper input validation vulnerability that allow…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.