A vulnerability in the web-based management interface of Cisco AsyncOS for Secure Email Gateway could allow an authenticated, remote attacker to execute arbitrary system commands on an affected device. This vulnerability is due to insufficient input validation in certain portions of the web-based management interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with root privileges. To successfully exploit this vulnerability, an attacker would need at least valid Operator credentials.
History

Fri, 08 Aug 2025 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco asyncos
Cisco secure Email Gateway C195
Cisco secure Email Gateway C395
Cisco secure Email Gateway C695
Cisco secure Email Gateway Virtual Appliance C100v
Cisco secure Email Gateway Virtual Appliance C300v
Cisco secure Email Gateway Virtual Appliance C600v
CPEs cpe:2.3:a:cisco:secure_email_gateway_virtual_appliance_c100v:-:*:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_email_gateway_virtual_appliance_c300v:-:*:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_email_gateway_virtual_appliance_c600v:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:secure_email_gateway_c195:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:secure_email_gateway_c395:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:secure_email_gateway_c695:-:*:*:*:*:*:*:*
cpe:2.3:o:cisco:asyncos:11.0.3-238:*:*:*:*:*:*:*
cpe:2.3:o:cisco:asyncos:11.1.0-069:*:*:*:*:*:*:*
cpe:2.3:o:cisco:asyncos:11.1.0-128:*:*:*:*:*:*:*
cpe:2.3:o:cisco:asyncos:11.1.0-131:*:*:*:*:*:*:*
cpe:2.3:o:cisco:asyncos:12.0.0-419:*:*:*:*:*:*:*
cpe:2.3:o:cisco:asyncos:12.1.0-071:*:*:*:*:*:*:*
cpe:2.3:o:cisco:asyncos:12.1.0-087:*:*:*:*:*:*:*
cpe:2.3:o:cisco:asyncos:12.1.0-089:*:*:*:*:*:*:*
cpe:2.3:o:cisco:asyncos:12.5.0-066:*:*:*:*:*:*:*
cpe:2.3:o:cisco:asyncos:12.5.3-041:*:*:*:*:*:*:*
cpe:2.3:o:cisco:asyncos:12.5.4-041:*:*:*:*:*:*:*
cpe:2.3:o:cisco:asyncos:13.0.0-392:*:*:*:*:*:*:*
cpe:2.3:o:cisco:asyncos:13.0.5-007:*:*:*:*:*:*:*
cpe:2.3:o:cisco:asyncos:13.5.1-277:*:*:*:*:*:*:*
cpe:2.3:o:cisco:asyncos:13.5.4-038:*:*:*:*:*:*:*
cpe:2.3:o:cisco:asyncos:14.0.0-698:*:*:*:*:*:*:*
cpe:2.3:o:cisco:asyncos:14.2.0-620:*:*:*:*:*:*:*
cpe:2.3:o:cisco:asyncos:14.2.1-020:*:*:*:*:*:*:*
Vendors & Products Cisco
Cisco asyncos
Cisco secure Email Gateway C195
Cisco secure Email Gateway C395
Cisco secure Email Gateway C695
Cisco secure Email Gateway Virtual Appliance C100v
Cisco secure Email Gateway Virtual Appliance C300v
Cisco secure Email Gateway Virtual Appliance C600v

cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published: 2024-07-17T16:29:18.884Z

Updated: 2024-08-01T21:59:41.996Z

Reserved: 2023-11-08T15:08:07.666Z

Link: CVE-2024-20429

cve-icon Vulnrichment

Updated: 2024-08-01T21:59:41.996Z

cve-icon NVD

Status : Analyzed

Published: 2024-07-17T17:15:14.497

Modified: 2025-08-08T01:56:39.500

Link: CVE-2024-20429

cve-icon Redhat

No data.