Vulnerability Database

296,172

Total vulnerabilities in the database

CVE-2024-20392

A vulnerability in the web-based management API of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack.

This vulnerability is due to insufficient input validation of some parameters that are passed to the web-based management API of the affected system. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to perform cross-site scripting (XSS) attacks, resulting in the execution of arbitrary script code in the browser of the targeted user, or could allow the attacker to access sensitive, browser-based information.

  • Published: May 15, 2024
  • Updated: Aug 7, 2025
  • CVE: CVE-2024-20392
  • Severity: Medium
  • Exploit:

CVSS v3:

  • Severity: Medium
  • Score: 6.1
  • AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

No CWE or OWASP classifications available.

Software From Fixed in
cisco / asyncos 11.0.3-238 11.0.3-238.x
cisco / asyncos 11.1.0-069 11.1.0-069.x
cisco / asyncos 11.1.0-128 11.1.0-128.x
cisco / asyncos 12.0.0-419 12.0.0-419.x
cisco / asyncos 12.1.0-071 12.1.0-071.x
cisco / asyncos 12.1.0-087 12.1.0-087.x
cisco / asyncos 12.1.0-089 12.1.0-089.x
cisco / asyncos 12.5.0-066 12.5.0-066.x
cisco / asyncos 12.5.3-041 12.5.3-041.x
cisco / asyncos 12.5.4-041 12.5.4-041.x
cisco / asyncos 13.0.0-392 13.0.0-392.x
cisco / asyncos 13.0.5-007 13.0.5-007.x
cisco / asyncos 13.5.1-277 13.5.1-277.x
cisco / asyncos 13.5.4-038 13.5.4-038.x
cisco / asyncos 14.0.0-698 14.0.0-698.x
cisco / asyncos 14.2.0-620 14.2.0-620.x
cisco / asyncos 14.2.1-020 14.2.1-020.x
cisco / asyncos 14.3.0-032 14.3.0-032.x
cisco / asyncos 15.0.0-104 15.0.0-104.x
cisco / asyncos 15.0.1-030 15.0.1-030.x
cisco / asyncos 15.5.0-048 15.5.0-048.x