CVE-2025-20393CRITICAL 10.0CISA KEVEPSS p97.9%
CVE-2025-20393Cisco Multiple Products Improper Input Validation Vulnerability
Cisco / Multiple Products
Description
Cisco Secure Email Gateway, Secure Email, AsyncOS Software, and Web Manager appliances contains an improper input validation vulnerability that allows threat actors to execute arbitrary commands with root privileges on the underlying operating system of an affected appliance.
Scoring
| CVSS 3.1 | 10.0 (CRITICAL) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 29.06% probability of exploitation · percentile 97.9% · 2026-06-18T12:00:27Z |
| Published | 2025-12-17 |
| Last modified | 2026-01-16 |
CISA KEV entry
Added to KEV: 2025-12-17
Underlying weaknesses· 1
References
1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Improper Input Validationcwe-20 | 0% | live |
(incoming)1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| KEVEntry | Cisco Multiple Products Improper Input Validation Vulnerabilitykev-cve-2025-20393 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.