New Tool Released to Detect Cisco Secure Email Gateway 0-Day Vulnerability Exploited in the Wild
ID: 9c38724e-bc07-5856-bab2-442e5bf20bf7
STIX ID: report--9c38724e-bc07-5856-bab2-442e5bf20bf7
Feed Name: cybersecurityNews.com
A publicly released, dependency-free Python script called "Cisco SMA Exposure Check" helps organizations detect exposure to CVE-2025-20393 — a critical unauthenticated RCE in Cisco Secure Email Gateway/SMA that is reported to be actively exploited. The tool probes admin and quarantine ports (e.g., 82, 83, 443, 8080, 8443, 9443, 6025), performs HTTP/S fingerprinting and path checks, and flags indicators of active exploitation and post-compromise tools (AquaShell, AquaTunnel, Chisel, AquaPurge), enabling rapid mitigation such as firewalling, patching, or isolation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
