CVE-2025-20244

7.7

Cisco · Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software

A vulnerability in the Remote Access SSL VPN service of Cisco ASA and FTD software allows an authenticated remote user to cause a device reload via a crafted HTTP request, resulting in a DoS.

Executive summary

An authenticated remote attacker can trigger a denial of service condition on Cisco Secure Firewall ASA and FTD devices by sending a specifically crafted HTTP request.

Vulnerability

The flaw exists due to improper validation of input when parsing HTTP header field values within the Remote Access SSL VPN service. An authenticated remote attacker can exploit this by sending a malformed request to the affected service, triggering an unexpected device reload.

Business impact

Successful exploitation results in a denial of service, forcing the network security appliance to reload. Given the critical role of VPN gateways in providing secure remote access, this disruption poses a significant risk to business continuity and availability of internal resources. With a CVSS score of 7.7, this vulnerability is classified as High severity, necessitating prompt attention to maintain infrastructure stability.

Remediation

Immediate Action: Review the official Cisco security advisory for available patches or configuration workarounds and apply them to all affected ASA and FTD deployments.

Proactive Monitoring: Monitor system logs for repeated VPN service crashes or unusual HTTP traffic patterns directed at the SSL VPN endpoint.

Compensating Controls: Ensure that access to the VPN interface is restricted to authorized IP ranges or implement robust authentication policies to minimize the potential pool of attackers who could trigger this vulnerability.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations utilizing Cisco ASA or FTD software should prioritize this update to prevent potential service disruptions. While the vulnerability requires authentication, the impact on availability is substantial, making it imperative to apply vendor-provided fixes as soon as they become available to ensure network resilience.

More Cisco CVEs

Sources