Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-20153

Опубликовано: 19 фев. 2025
Источник: nvd
CVSS3: 5.8
CVSS3: 5.3
EPSS Низкий

Описание

A vulnerability in the email filtering mechanism of Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to bypass the configured rules and allow emails that should have been denied to flow through an affected device.  

This vulnerability is due to improper handling of email that passes through an affected device. An attacker could exploit this vulnerability by sending a crafted email through the affected device. A successful exploit could allow the attacker to bypass email filters on the affected device.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:cisco:secure_email_gateway:13.0.0-392:*:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_email_gateway:13.0.5-007:*:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_email_gateway:13.5.1-277:*:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_email_gateway:13.5.4-038:*:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_email_gateway:14.0.0-698:*:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_email_gateway:14.2.0-620:*:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_email_gateway:14.2.1-020:*:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_email_gateway:14.3.0-032:*:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_email_gateway:15.0.0-104:*:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_email_gateway:15.0.1-030:*:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_email_gateway:15.0.3-002:*:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_email_gateway:15.5.0-048:*:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_email_gateway:15.5.1-055:*:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_email_gateway:15.5.2-018:*:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_email_gateway:16.0.0-050:*:*:*:*:*:*:*

EPSS

Процентиль: 27%
0.00094
Низкий

5.8 Medium

CVSS3

5.3 Medium

CVSS3

Дефекты

CWE-284
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 5.8
github
12 месяцев назад

A vulnerability in the email filtering mechanism of Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to bypass the configured rules and allow emails that should have been denied to flow through an affected device.   This vulnerability is due to improper handling of email that passes through an affected device. An attacker could exploit this vulnerability by sending a crafted email through the affected device. A successful exploit could allow the attacker to bypass email filters on the affected device.

CVSS3: 5.8
fstec
12 месяцев назад

Уязвимость системы обеспечения безопасности электронной почты Cisco Secure Email Gateway операционной системы Cisco AsyncOS, позволяющая нарушителю обойти существующие ограничения безопасности

EPSS

Процентиль: 27%
0.00094
Низкий

5.8 Medium

CVSS3

5.3 Medium

CVSS3

Дефекты

CWE-284
NVD-CWE-noinfo