CVE-2025-20127

7.7

Cisco · Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software

A resource consumption vulnerability in the TLS 1.3 implementation of Cisco Secure Firewall software allows authenticated remote attackers to cause a denial of service on affected appliances.

Executive summary

An authenticated, remote denial of service vulnerability in Cisco Secure Firewall (ASA and FTD) software allows attackers to crash SSL/TLS and VPN services by exhausting system resources.

Vulnerability

This flaw exists in the implementation of the TLS 1.3 cipher TLS_CHACHA20_POLY1305_SHA256, where an authenticated remote attacker can consume system resources by sending a high volume of specific TLS 1.3 connections, leading to a denial of service.

Business impact

A successful exploitation of this vulnerability results in a denial of service condition, effectively halting all new encrypted connections, including VPN and user management traffic. Given the CVSS score of 7.7, this represents a high-severity risk to business continuity, as the affected device must be manually reloaded to restore normal operations.

Remediation

Immediate Action: Consult the official Cisco security advisory for available software patches and apply the necessary updates to the affected firewall appliances.

Proactive Monitoring: Monitor firewall logs and connection rates for an anomalous surge in TLS 1.3 connection attempts or unusual patterns involving the specified cipher suite.

Compensating Controls: While a direct patch is the primary requirement, ensure that management interfaces are restricted to trusted networks to limit the pool of potential authenticated attackers.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

The risk posed by this vulnerability is significant for organizations relying on Cisco Firepower 3100 and 4200 series devices for secure connectivity. Administrators should prioritize the application of vendor-supplied patches as soon as they are made available to prevent potential service outages caused by resource exhaustion.

More Cisco CVEs

Sources