Vulnslist

find the latest Cisco vulnerabilities

CVE-2025-20183

A vulnerability in a policy-based Cisco Application Visibility and Control (AVC) implementation of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to evade the antivirus scanner and download a malicious file onto an endpoint.  The vulnerability is due to improper handling of a crafted range request header. An attacker could exploit this vulnerability by sending an HTTP request with a crafted range request header through the affected device. A successful exploit could allow the attacker to evade the antivirus scanner and download malware onto the endpoint without detection by Cisco Secure Web Appliance.

SeverityMEDIUM
CVSS5.8
EPSS0.29%
CWECWE-20
KEV
Published
Modified

CSAF Product Statuses

Product Status Source Advisory Rows
Cisco Secure Web Appliance known_affected cisco_csaf cisco-sa-swa-range-bypass-2BsEHYSu 1

Related Products

Product Advisory
Application Visibility and Control (AVC) cisco-sa-swa-range-bypass-2BsEHYSu
Cisco Secure Web Appliance cisco-sa-swa-range-bypass-2BsEHYSu
Cisco Application Visibility and Control (AVC) cisco-sa-swa-range-bypass-2BsEHYSu