A vulnerability in the email filtering mechanism of Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to bypass the configured rules and allow emails that should have been denied to flow through an affected device.
This vulnerability is due to improper handling of email that passes through an affected device. An attacker could exploit this vulnerability by sending a crafted email through the affected device. A successful exploit could allow the attacker to bypass email filters on the affected device.
Metrics
Affected Vendors & Products
References
History
Thu, 31 Jul 2025 12:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Cisco
Cisco secure Email Gateway |
|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:a:cisco:secure_email_gateway:13.0.0-392:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_email_gateway:13.0.5-007:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_email_gateway:13.5.1-277:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_email_gateway:13.5.4-038:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_email_gateway:14.0.0-698:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_email_gateway:14.2.0-620:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_email_gateway:14.2.1-020:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_email_gateway:14.3.0-032:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_email_gateway:15.0.0-104:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_email_gateway:15.0.1-030:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_email_gateway:15.0.3-002:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_email_gateway:15.5.0-048:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_email_gateway:15.5.1-055:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_email_gateway:15.5.2-018:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_email_gateway:16.0.0-050:*:*:*:*:*:*:* |
|
Vendors & Products |
Cisco
Cisco secure Email Gateway |
Wed, 19 Feb 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 19 Feb 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability in the email filtering mechanism of Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to bypass the configured rules and allow emails that should have been denied to flow through an affected device. This vulnerability is due to improper handling of email that passes through an affected device. An attacker could exploit this vulnerability by sending a crafted email through the affected device. A successful exploit could allow the attacker to bypass email filters on the affected device. | |
Title | Cisco ESA mail Bypass | |
Weaknesses | CWE-284 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: cisco
Published: 2025-02-19T16:06:10.664Z
Updated: 2025-02-19T16:19:19.168Z
Reserved: 2024-10-10T19:15:13.216Z
Link: CVE-2025-20153

Updated: 2025-02-19T16:19:07.341Z

Status : Analyzed
Published: 2025-02-19T16:15:40.860
Modified: 2025-07-31T12:40:47.020
Link: CVE-2025-20153

No data.