📦 Asyncos

by Cisco

🔍 What is Asyncos?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-20393

CRITICAL CVSS 10.0 Dec 17, 2025

An unauthenticated remote attacker can execute arbitrary system commands with root privileges on Cisco Secure Email Gateway and Cisco Secure Email and Web Manager devices. This occurs due to insuffici...

CVE-2024-20435

HIGH CVSS 8.8 Jul 17, 2024

This vulnerability in Cisco AsyncOS for Secure Web Appliance allows authenticated local attackers with guest credentials to execute arbitrary commands and escalate privileges to root via insufficient ...

CVE-2022-20653

HIGH CVSS 7.5 Feb 17, 2022

This vulnerability in Cisco Email Security Appliance's DANE email verification allows unauthenticated remote attackers to cause denial of service by sending specially crafted emails. The insufficient ...

CVE-2025-20183

MEDIUM CVSS 5.8 Feb 5, 2025

This vulnerability allows unauthenticated remote attackers to bypass the antivirus scanner on Cisco Secure Web Appliance by sending crafted HTTP range request headers. Affected organizations using Cis...

CVE-2021-1425

MEDIUM CVSS 4.3 Nov 18, 2024

This vulnerability in Cisco Content Security Management Appliance (SMA) allows authenticated remote attackers to access sensitive information, including passwords, by intercepting HTTP requests betwee...

CVE-2024-20504

MEDIUM CVSS 5.4 Nov 6, 2024

This stored XSS vulnerability in Cisco AsyncOS web management interfaces allows authenticated attackers to inject malicious scripts that execute when other users view affected pages. It affects Cisco ...

CVE-2024-20392

MEDIUM CVSS 6.1 May 15, 2024

An HTTP response splitting vulnerability in Cisco Secure Email Gateway's web management API allows unauthenticated attackers to conduct cross-site scripting attacks. By tricking users into clicking ma...

CVE-2024-20383

MEDIUM CVSS 4.8 May 15, 2024

This vulnerability allows authenticated attackers to conduct cross-site scripting (XSS) attacks against users of Cisco Secure Email and Web Manager's web interface. Attackers can inject malicious scri...

CVE-2024-20257

MEDIUM CVSS 4.8 May 15, 2024

This cross-site scripting (XSS) vulnerability in Cisco Secure Email Gateway's web management interface allows authenticated attackers to inject malicious scripts. When exploited, it can compromise use...