One crafted email can give an unauthenticated attacker root command execution on Cisco Secure Email Gateway.
No management access or recipient action is required.
Cisco Secure Email Gateway, physical and virtual email-security appliances running AsyncOS.
Unauthenticated root command execution through email delivery
The gateway processes the hostile object itself, and Cisco reports exploitation of the message-to-database-to-root path.
Detail and 4 sources
Insufficient parser validation lets crafted SQL reach the appliance database; PostgreSQL program execution then reaches operating-system commands running as root.
Cisco reports exploitation and has published fixed AsyncOS releases. Pre-fix images remain accepted.
- access:network:internet
- reachable from the public internet
- interaction:none
- no user action required
- Pre-fix images still accepted
- Yes
- Reaches end-of-life hardware
- No
Cisco’s x90 hardware notice places the last date of support and vulnerability/security support at September 30, 2025.