Vulnerability Database

296,172

Total vulnerabilities in the database

CVE-2025-20180

A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Email Gateway could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface.

This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker must have valid credentials for a user account with at least the role of Operator.

  • Published: Feb 5, 2025
  • Updated: May 4, 2025
  • CVE: CVE-2025-20180
  • Severity: Low
  • Exploit:

CVSS v3:

  • Severity: Low
  • Score: 4.8
  • AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Software From Fixed in
cisco / asyncos 12.8.1-002 12.8.1-002.x
cisco / asyncos 12.8.1-021 12.8.1-021.x
cisco / asyncos 13.0.0-249 13.0.0-249.x
cisco / asyncos 13.0.0-277 13.0.0-277.x
cisco / asyncos 13.6.1-201 13.6.1-201.x
cisco / asyncos 13.6.2-023 13.6.2-023.x
cisco / asyncos 13.6.2-078 13.6.2-078.x
cisco / asyncos 13.8.1-052 13.8.1-052.x
cisco / asyncos 13.8.1-068 13.8.1-068.x
cisco / asyncos 13.8.1-074 13.8.1-074.x
cisco / asyncos 13.8.1-108 13.8.1-108.x
cisco / asyncos 14.0.0-404 14.0.0-404.x
cisco / asyncos 14.1.0-227 14.1.0-227.x
cisco / asyncos 14.2.0-203 14.2.0-203.x
cisco / asyncos 14.2.0-212 14.2.0-212.x
cisco / asyncos 14.2.0-224 14.2.0-224.x
cisco / asyncos 14.3.0-120 14.3.0-120.x
cisco / asyncos 15.0.0-334 15.0.0-334.x
cisco / asyncos 15.5.1-024 15.5.1-024.x
cisco / asyncos 15.5.1-029 15.5.1-029.x
cisco / asyncos 15.5.2-005 15.5.2-005.x
cisco / asyncos 16.0.0-195 16.0.0-195.x
cisco / asyncos 13.0.0-392 13.0.0-392.x
cisco / asyncos 13.0.5-007 13.0.5-007.x
cisco / asyncos 13.5.1-277 13.5.1-277.x
cisco / asyncos 13.5.4-038 13.5.4-038.x
cisco / asyncos 14.0.0-698 14.0.0-698.x
cisco / asyncos 14.2.0-620 14.2.0-620.x
cisco / asyncos 14.2.1-020 14.2.1-020.x
cisco / asyncos 14.3.0-032 14.3.0-032.x
cisco / asyncos 15.0.0-104 15.0.0-104.x
cisco / asyncos 15.0.1-030 15.0.1-030.x
cisco / asyncos 15.0.3-002 15.0.3-002.x
cisco / asyncos 15.5.0-048 15.5.0-048.x
cisco / asyncos 15.5.1-055 15.5.1-055.x
cisco / asyncos 15.5.2-018 15.5.2-018.x
cisco / asyncos 16.0.0-050 16.0.0-050.x
cisco / asyncos 16.0.0-054 16.0.0-054.x