CVE-2025-20183

Cisco Secure Web Appliance Range Request Bypass Vulnerability

Severity
Medium 5.8
CVSS 3.1
Exploited
Not listed
EPSS
0.004
34.8th percentile
Discovered by
Third party
Published by the vendor
Published
Feb 5, 2025
Assigned by cisco

Description

A vulnerability in a policy-based Cisco Application Visibility and Control (AVC) implementation of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to evade the antivirus scanner and download a malicious file onto an endpoint.  The vulnerability is due to improper handling of a crafted range request header. An attacker could exploit this vulnerability by sending an HTTP request with a crafted range request header through the affected device. A successful exploit could allow the attacker to evade the antivirus scanner and download malware onto the endpoint without detection by Cisco Secure Web Appliance.

Weakness: CWE-20

Affected products

Vendor Product Category Matched by
Cisco Cisco Secure Web Appliance SASE / SSE / Secure Web cna-assigner
Vendor-reported affected versions (1)
  • Cisco · Cisco Secure Web Appliance