CVE-2025-20134
8.6Cisco · Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software
A double free vulnerability in Cisco ASA and FTD software allows unauthenticated remote attackers to trigger a device reload and denial of service via crafted SSL/TLS certificate packets.
Executive summary
An unauthenticated remote denial of service vulnerability in Cisco Secure Firewall ASA and FTD software poses a significant risk to network availability.
Vulnerability
This flaw is a double free vulnerability (CWE-415) caused by improper parsing of SSL/TLS certificates. An unauthenticated attacker can trigger this condition by sending crafted DNS packets through devices that have static NAT rules with DNS inspection enabled.
Business impact
Successful exploitation results in an unexpected device reload, causing a denial of service for all traffic traversing the firewall. Given the CVSS score of 8.6, this vulnerability represents a high-severity threat to business continuity, as it allows attackers to disrupt critical network infrastructure without requiring authentication.
Remediation
Immediate Action: Organizations must update the affected Cisco ASA and FTD software to the versions specified in the official Cisco security advisory.
Proactive Monitoring: Security teams should monitor firewall logs and system health dashboards for unexpected reloads or recurring spikes in malformed traffic patterns.
Compensating Controls: If immediate patching is not feasible, consider disabling DNS inspection on static NAT rules where possible, or implement perimeter filtering to block unauthorized traffic targeting the firewall management or inspection interfaces.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The high severity of this vulnerability, combined with the ease of exploitation, necessitates an immediate review of all deployed Cisco ASA and FTD instances. Administrators should prioritize the application of vendor-supplied patches to prevent potential service disruption and ensure the continued stability of the network perimeter.