CVE-2025-20183: Cisco Secure Web Appliance Range Request Bypass Vulnerability
A vulnerability in a policy-based Cisco Application Visibility and Control (AVC) implementation of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to evade the antivirus scanner and download a malicious file onto an endpoint. The vulnerability is due to improper handling of a crafted range request header. An attacker could exploit this vulnerability by sending an HTTP request with a crafted range request header through the affected device. A successful exploit could allow the attacker to evade the antivirus scanner and download malware onto the endpoint without detection by Cisco Secure Web Appliance.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20183?
CVE-2025-20183 has been classified with a high severity due to its potential impact on system security.
How do I fix CVE-2025-20183?
To fix CVE-2025-20183, you should apply the latest updates provided by Cisco for the Cisco Secure Web Appliance.
What type of attack can exploit CVE-2025-20183?
CVE-2025-20183 can be exploited by an unauthenticated remote attacker to evade antivirus scanning.
What software versions are affected by CVE-2025-20183?
CVE-2025-20183 affects implementations of Cisco AsyncOS Software on Cisco Secure Web Appliance.
Is authentication required to exploit CVE-2025-20183?
No, authentication is not required for an attacker to exploit CVE-2025-20183.