CVE-2025-20183: Cisco Asyncos
Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.
A vulnerability in a policy-based Cisco Application Visibility and Control (AVC) implementation of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to evade the antivirus scanner and download a malicious file onto an endpoint. The vulnerability is due to improper handling of a crafted range request header. An attacker could exploit this vulnerability by sending an HTTP request with a crafted range request header through the affected device. A successful exploit could allow the attacker to evade the antivirus scanner and download malware onto the endpoint without detection by Cisco Secure Web Appliance.
Affected products
- Cisco Asyncos: version 11.8.0-414 only; version 11.8.0-429 only; version 11.8.0-453 only; version 11.8.1-023 only; version 11.8.3-018 only; version 11.8.3-021 only; …
Published 2025-02-05. Last modified 2026-06-17.