Cisco
Cisco Asyncos: vulnerabilidades y CVE
Cisco Asyncos tiene 57 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 2 son críticas y 2 figuran en el catálogo de explotación activa de CISA.
CVE57
Últimos 12 meses4
Críticas2
Explotadas activamente2
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-76461 | Crítica (9.8) | 28% | ⚠ Explotación activa | 14 sept 2026 | A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying… |
| CVE-2025-20393 | Crítica (10) | 32% | ⚠ Explotación activa | 17 dic 2025 | A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to execute arbitrary system… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-76461 | Crítica (9.8) | 28% | ⚠ Explotación activa | 14 sept 2026 | A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying… |
| CVE-2026-20152 | Media (5.3) | 0.30% | — | 15 abr 2026 | A vulnerability in the authentication service feature of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to bypass authentication policy requirements. This… |
| CVE-2026-20056 | Media (4) | 0.16% | — | 4 feb 2026 | A vulnerability in the Dynamic Vectoring and Streaming (DVS) Engine implementation of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to bypass the anti-malware… |
| CVE-2025-20393 | Crítica (10) | 32% | ⚠ Explotación activa | 17 dic 2025 | A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to execute arbitrary system… |
| CVE-2020-3122 | Media (5.3) | 0.39% | — | 4 mar 2025 | A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to obtain sensitive network information. |
| CVE-2025-20185 | Media (6.7) | 0.19% | — | 5 feb 2025 | A vulnerability in the implementation of the remote access functionality of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, Cisco Secure Email Gateway, and Cisco Secure Web Appliance could allow an… |
| CVE-2025-20184 | Alta (7.2) | 0.86% | — | 5 feb 2025 | A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Web Appliance could allow an authenticated, remote attacker to perform command injection… |
| CVE-2025-20183 | Media (5.3) | 0.44% | — | 5 feb 2025 | The vulnerability is due to improper handling of a crafted range request header. An attacker could exploit this vulnerability by sending an HTTP request with a crafted range request header through the affected device. A… |
| CVE-2025-20180 | Media (4.8) | 0.32% | — | 5 feb 2025 | A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Email Gateway could allow an authenticated, remote attacker to conduct a stored… |
| CVE-2021-1425 | Media (6.5) | 0.53% | — | 18 nov 2024 | A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Content Security Management Appliance (SMA) could allow an authenticated, remote attacker to access sensitive… |
| CVE-2022-20871 | Alta (8.8) | 1.9% | — | 15 nov 2024 | A vulnerability in the web management interface of Cisco AsyncOS for Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow an authenticated, remote attacker to perform… |
| CVE-2024-20504 | Media (5.4) | 0.28% | — | 6 nov 2024 | A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, Secure Email Gateway, and Secure Web Appliance could allow an authenticated, remote attacker to… |
| CVE-2024-20435 | Alta (7.8) | 0.16% | — | 17 jul 2024 | A vulnerability in the CLI of Cisco AsyncOS for Secure Web Appliance could allow an authenticated, local attacker to execute arbitrary commands and elevate privileges to root. This vulnerability is due to insufficient… |
| CVE-2024-20429 | Alta (7.2) | 0.62% | — | 17 jul 2024 | A vulnerability in the web-based management interface of Cisco AsyncOS for Secure Email Gateway could allow an authenticated, remote attacker to execute arbitrary system commands on an affected device. This… |
| CVE-2024-20392 | Media (6.1) | 0.39% | — | 15 may 2024 | A vulnerability in the web-based management API of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack. This vulnerability… |
| CVE-2024-20383 | Alta (8.4) | 0.35% | — | 15 may 2024 | A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager could allow an authenticated, remote attacker to conduct an XSS attack against a user of the… |
| CVE-2024-20258 | Media (6.1) | 0.32% | — | 15 may 2024 | A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Email Gateway could allow an unauthenticated, remote attacker to conduct an XSS attack… |
| CVE-2024-20257 | Media (4.8) | 0.29% | — | 15 may 2024 | A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface.r… |
| CVE-2024-20256 | Media (4.8) | 0.29% | — | 15 may 2024 | A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Web Appliance could allow an authenticated, remote attacker to conduct an XSS attack… |
| CVE-2020-26082 | Media (5.3) | 0.63% | — | 4 ago 2023 | A vulnerability in the zip decompression engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass content filters that are configured on an… |
| CVE-2023-20215 | Media (5.3) | 0.62% | — | 3 ago 2023 | A vulnerability in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to bypass a configured rule, allowing traffic onto a network that should… |
| CVE-2022-20952 | Media (5.3) | 0.68% | — | 1 mar 2023 | A vulnerability in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance, formerly known as Cisco Web Security Appliance (WSA), could allow an unauthenticated, remote attacker to bypass a… |
| CVE-2023-20057 | Media (5.3) | 0.68% | — | 20 ene 2023 | A vulnerability in the URL filtering mechanism of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the URL reputation filters on an affected… |
| CVE-2022-20942 | Media (6.5) | 0.95% | — | 4 nov 2022 | A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA), Cisco Secure Email and Web Manager, and Cisco Secure Web Appliance, formerly known as Cisco Web Security Appliance (WSA),… |
| CVE-2022-20868 | Alta (8.8) | 0.74% | — | 4 nov 2022 | A vulnerability in the web-based management interface of Cisco Email Security Appliance, Cisco Secure Email and Web Manager and Cisco Secure Web Appliance could allow an authenticated, remote attacker to elevate… |
| CVE-2022-20867 | Media (6.5) | 0.80% | — | 4 nov 2022 | A vulnerability in web-based management interface of the of Cisco Email Security Appliance and Cisco Secure Email and Web Manager could allow an authenticated, remote attacker to conduct SQL injection attacks as root on… |
| CVE-2022-20781 | Media (5.4) | 0.58% | — | 6 abr 2022 | A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack… |
| CVE-2022-20675 | Media (5.3) | 1.3% | — | 6 abr 2022 | A vulnerability in the TCP/IP stack of Cisco Email Security Appliance (ESA), Cisco Web Security Appliance (WSA), and Cisco Secure Email and Web Manager, formerly Security Management Appliance, could allow an… |
| CVE-2022-20653 | Alta (7.5) | 1.8% | — | 17 feb 2022 | A vulnerability in the DNS-based Authentication of Named Entities (DANE) email verification component of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to… |
| CVE-2021-34741 | Alta (7.5) | 1.3% | — | 4 nov 2021 | A vulnerability in the email scanning algorithm of Cisco AsyncOS software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to perform a denial of service (DoS) attack against an… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.