CVE-2025-20393
CISA 기관 조치 기한: 2025-12-24
Cisco Multiple Products
Qualys 위협 인텔 · 심각도 5/5 · QID 317752 · Cisco
제로데이
공개 익스플로잇
실제 공격 관측
측면이동
쉬운 악용
대량 데이터 유출
서비스 거부
패치 없음
웜 전파
권한상승
인증 불필요
원격코드실행
CISA KEV
Cisco Secure Email Gateway, Secure Email, AsyncOS Software, and Web Manager appliances contains an improper input validation vulnerability that allows threat actors to execute arbitrary commands with root privileges on the underlying operating system of an affected appliance.
KEV 필수 조치: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
벡터: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H