Cisco Secure Email Gateway
cpe:2.3:a:cisco:secure_email_gateway:*:*:*:*:*:*:*, +2 more
This vulnerability is being actively exploited in the wild.
A vulnerability in Cisco Secure Email Gateway and Cisco Secure Email and Web Manager appliances, both physical and virtual, has been identified. This vulnerability allows threat actors to execute arbitrary commands with root privileges on the underlying operating system of affected appliances. The issue arises from improper input validation and affects all releases of Cisco AsyncOS Software. The vulnerability is exploitable when the Spam Quarantine feature is enabled and exposed to the internet.
Exploitation of this vulnerability allows for unauthorized execution of commands with root privileges, potentially leading to a complete compromise of the affected appliance's operating system.
Cisco recommends upgrading to the latest version of Cisco AsyncOS Software. For Cisco Secure Email Gateway, separate mail and management functionality onto different network interfaces to reduce the risk of unauthorized access. For Cisco Secure Email and Web Manager, ensure that the Spam Quarantine feature is not exposed to the internet. If an appliance has been compromised, rebuilding it is currently the only way to remove the threat actor's persistence mechanism.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.