CVE-2025-20153: Cisco Secure Email Gateway

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

A vulnerability in the email filtering mechanism of Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to bypass the configured rules and allow emails that should have been denied to flow through an affected device.   This vulnerability is due to improper handling of email that passes through an affected device. An attacker could exploit this vulnerability by sending a crafted email through the affected device. A successful exploit could allow the attacker to bypass email filters on the affected device.

Affected products

  • Cisco Secure Email Gateway: version 13.0.0-392 only; version 13.0.5-007 only; version 13.5.1-277 only; version 13.5.4-038 only; version 14.0.0-698 only; version 14.2.0-620 only; …

Published 2025-02-19. Last modified 2026-06-17.