Secure Email and Web
CVE-2025-20183: Cisco Secure Web Appliance Range Request Bypass Vulnerability
A vulnerability in a policy-based Cisco Application Visibility and Control (AVC) implementation of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to evade the antivirus scanner and download a malicious file onto an endpoint. The vulnerability is due to improper handling of a crafted range request header.
Published
Automatic summary from the vendor's CVE record. We haven't written a full analysis of this vulnerability yet.
Affected and fixed versions
| Product / branch | Fixed in |
|---|---|
| Cisco Secure Web Appliance 11.8 | See the advisory |
| Cisco Secure Web Appliance 12.5 | See the advisory |
| Cisco Secure Web Appliance 12.0 | See the advisory |
| Cisco Secure Web Appliance 12.0 | See the advisory |
| Cisco Secure Web Appliance 14.1 | See the advisory |
| Cisco Secure Web Appliance 14.1 | See the advisory |
| Cisco Secure Web Appliance 14.1 | See the advisory |
| Cisco Secure Web Appliance 12.0 | See the advisory |
| Cisco Secure Web Appliance 14.0 | See the advisory |
| Cisco Secure Web Appliance 11.8 | See the advisory |
| Cisco Secure Web Appliance 12.0 | See the advisory |
| Cisco Secure Web Appliance 11.8 | See the advisory |
| Cisco Secure Web Appliance 11.8 | See the advisory |
| Cisco Secure Web Appliance 11.8 | See the advisory |
| Cisco Secure Web Appliance 12.5 | See the advisory |
| Cisco Secure Web Appliance 11.8 | See the advisory |
| Cisco Secure Web Appliance 12.5 | See the advisory |
| Cisco Secure Web Appliance 12.5 | See the advisory |
| Cisco Secure Web Appliance 14.5 | See the advisory |
| Cisco Secure Web Appliance 12.5 | See the advisory |
| Cisco Secure Web Appliance 12.5 | See the advisory |
| Cisco Secure Web Appliance 12.0 | See the advisory |
| Cisco Secure Web Appliance 14.0 | See the advisory |
| Cisco Secure Web Appliance 12.5 | See the advisory |
| Cisco Secure Web Appliance 12.5 | See the advisory |
| Cisco Secure Web Appliance 12.5 | See the advisory |
| Cisco Secure Web Appliance 14.0 | See the advisory |
| Cisco Secure Web Appliance 14.5 | See the advisory |
| Cisco Secure Web Appliance 14.5 | See the advisory |
| Cisco Secure Web Appliance 15.0 | See the advisory |
| Cisco Secure Web Appliance 15.0 | See the advisory |
| Cisco Secure Web Appliance 12.5 | See the advisory |
| Cisco Secure Web Appliance 15.1 | See the advisory |
| Cisco Secure Web Appliance 14.5 | See the advisory |
| Cisco Secure Web Appliance 15.2 | See the advisory |
| Cisco Secure Web Appliance 14.0 | See the advisory |
| Cisco Secure Web Appliance 15.2 | See the advisory |
| Cisco Secure Web Appliance 14.5 | See the advisory |
| Cisco Secure Web Appliance 12.0 | See the advisory |
| Cisco Secure Web Appliance 12.0 | See the advisory |
| Cisco Secure Web Appliance 14.5 | See the advisory |
| Cisco Secure Web Appliance 14.5 | See the advisory |
| Cisco Secure Web Appliance 14.5 | See the advisory |
| Cisco Secure Web Appliance 14.5 | See the advisory |
| Cisco Secure Web Appliance 12.0 | See the advisory |
| Cisco Secure Web Appliance 14.0 | See the advisory |
| Cisco Secure Web Appliance 14.0 | See the advisory |
| Cisco Secure Web Appliance 11.8 | See the advisory |
| Cisco Secure Web Appliance 14.0 | See the advisory |
| Cisco Secure Web Appliance 14.0 | See the advisory |
| Cisco Secure Web Appliance 12.5 | See the advisory |
Always confirm against the vendor advisory, which lists every fixed hotfix.
What it is
A vulnerability in a policy-based Cisco Application Visibility and Control (AVC) implementation of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to evade the antivirus scanner and download a malicious file onto an endpoint.
The vulnerability is due to improper handling of a crafted range request header. An attacker could exploit this vulnerability by sending an HTTP request with a crafted range request header through the affected device. A successful exploit could allow the attacker to evade the antivirus scanner and download malware onto the endpoint without detection by Cisco Secure Web Appliance.
Exploitation
The Cisco PSIRT is not aware of any public announcements or malicious use of the vulnerability that is described in this advisory.
Sources
KEV status, EPSS score and vendor data refreshed automatically, last on 11 Oct 2026.