CVE-2025-20222

8.6

Cisco · Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)

A buffer overflow vulnerability in the Cisco ASA and FTD RADIUS proxy feature allows unauthenticated remote attackers to cause a denial of service via malformed IPv6 packets.

Executive summary

A critical denial of service vulnerability in Cisco Secure Firewall ASA and FTD software allows unauthenticated remote attackers to crash affected devices by sending malicious IPv6 packets.

Vulnerability

This vulnerability is a buffer overflow (CWE-120) triggered by improper processing of IPv6 packets within the RADIUS proxy feature for IPsec VPN connections. An unauthenticated remote attacker can exploit this flaw by sending specifically crafted IPv6 traffic to the device, forcing a system reload.

Business impact

The ability for an unauthenticated attacker to trigger a device reload poses a significant risk to network availability. Because this impacts VPN infrastructure, a successful exploit could disconnect remote workers, disrupt site-to-site tunnels, and cause widespread operational downtime. With a CVSS score of 8.6, this vulnerability represents a high-severity threat that requires immediate attention to prevent service interruption.

Remediation

Immediate Action: Review the official Cisco security advisory and apply the recommended software updates or configuration workarounds provided by the vendor.

Proactive Monitoring: Monitor device logs for unexpected system reloads or high volumes of malformed IPv6 traffic directed at VPN endpoints.

Compensating Controls: If patching is delayed, restrict access to the affected VPN endpoints to known, trusted IP ranges to reduce the attack surface.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the potential for complete service disruption of VPN connectivity, administrators should treat this vulnerability with high urgency. Prioritize identifying vulnerable Cisco ASA and FTD instances within your environment and apply the necessary vendor-supplied patches as soon as they are available to ensure network stability and security.

More Cisco CVEs

Sources