CNNVD-202512-3279 Information

CNNVD ID

CNNVD-202512-3279

CVE-2025-20393

  • CNNVD Published: 2025-12-17

Description (Chinese)

Cisco Secure Email和Cisco Secure Email and Web Manager都是美国思科(Cisco)公司的产品。Cisco Secure Email是思科安全电子邮件(前身为电子邮件安全)为您的电子邮件提供最佳保护,使其免受网络威胁。Cisco Secure Email and Web Manager是一个安全电子邮件和 Web 管理器。 Cisco Secure Email和Cisco Secure Email and Web Manager存在安全漏洞。攻击者利用该漏洞可以以root权限执行任意命令。

Description (English)

Cisco Security Email and Cisco Security Email and Web Manager are all Cisco products. Cisco Security Email is a Cisco secure e-mail (formerly e-mail security) that provides the best protection against cyber-threats. Cisco Security Email and Web Manager is a secure email and Web manager. Cisco Security Email and Cisco Security Email and Web Manager have security loopholes. The attackers took advantage of the loophole to enforce arbitrary orders with root authority.

Hazard Level

Low

Vulnerability Type

其他

Affected Vendor

思科

Published

2025-12-17

Last Modified

2026-02-24

References

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sma-attack-N9bf4 https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-20393 https://access.redhat.com/security/cve/cve-2025-20393

Patch

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sma-attack-N9bf4

Share on: