CVE-2025-20243

8.6

Cisco · Secure Firewall ASA Software and Secure FTD Software

A vulnerability in Cisco Secure Firewall ASA and FTD software allows unauthenticated remote attackers to cause a device reload, resulting in a denial of service condition.

Executive summary

Cisco Secure Firewall ASA and FTD software are vulnerable to an unauthenticated remote denial of service attack that can force an unexpected device reload.

Vulnerability

This vulnerability, categorized as an infinite loop (CWE-835), arises from improper validation of user-supplied input on the management and VPN web interfaces. An unauthenticated attacker can trigger this condition by sending crafted HTTP requests to the target device.

Business impact

The exploitation of this flaw leads to a denial of service, which disrupts critical network security and VPN connectivity. With a CVSS score of 8.6, the vulnerability is classified as High severity, reflecting the ease of exploitation and the significant impact on availability for organizations relying on these appliances for perimeter defense and remote access.

Remediation

Immediate Action: Review the official Cisco security advisory for available firmware updates and apply them to all affected ASA and FTD appliances as a priority.

Proactive Monitoring: Monitor system logs for unusual HTTP request patterns or repeated, unexplained device reloads that may indicate an attempt to trigger the vulnerability.

Compensating Controls: Restrict access to the management and VPN web interfaces to known, trusted IP addresses using access control lists to reduce the attack surface.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high CVSS score and the critical nature of Cisco firewall appliances in network infrastructure, administrators must treat this vulnerability with high urgency. Organizations should prioritize the identification of affected hardware and apply vendor-provided patches as soon as they are made available to ensure continued service availability and network integrity.

More Cisco CVEs

Sources