CVE-2025-20183

MEDIUM

Cisco AsyncOS - Unauthenticated Antivirus Scanner Bypass via Crafted Range Request Header

Title source: llm
STIX 2.1

Description

A vulnerability in a policy-based Cisco Application Visibility and Control (AVC) implementation of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to evade the antivirus scanner and download a malicious file onto an endpoint.  The vulnerability is due to improper handling of a crafted range request header. An attacker could exploit this vulnerability by sending an HTTP request with a crafted range request header through the affected device. A successful exploit could allow the attacker to evade the antivirus scanner and download malware onto the endpoint without detection by Cisco Secure Web Appliance.

Scores

CVSS v3 5.8
EPSS 0.0029
EPSS Percentile 52.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (50)
cisco/asyncos 11.8.0-414
cisco/asyncos 11.8.0-429
cisco/asyncos 11.8.0-453
cisco/asyncos 11.8.1-023
cisco/asyncos 11.8.3-018
cisco/asyncos 11.8.3-021
cisco/asyncos 11.8.4-004
cisco/asyncos 12.0.1-268
cisco/asyncos 12.0.1-334
cisco/asyncos 12.0.2-004
... and 40 more
Published Feb 05, 2025
Tracked Since Feb 18, 2026