CVE-2025-20333

9.9 CISA KEV

Cisco · Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)

A buffer overflow vulnerability in the VPN web server of Cisco ASA and FTD software allows an authenticated attacker to execute arbitrary code as root via crafted HTTP requests.

Executive summary

This critical vulnerability in Cisco Secure Firewall products is actively exploited in the wild and enables remote code execution with root privileges.

Vulnerability

This is a classic buffer overflow flaw (CWE-120) triggered by improper validation of user-supplied input in HTTP(S) requests. While the vulnerability requires an authenticated user, it is frequently chained with other flaws to facilitate unauthenticated access.

Business impact

A successful exploit grants the attacker complete control over the affected firewall device with root-level privileges. Given the CVSS score of 9.9, this represents a critical threat to network integrity, potentially allowing for full system compromise, traffic interception, or lateral movement within the enterprise environment. The risk is compounded by the fact that this vulnerability is being actively leveraged by sophisticated state-sponsored threat actors.

Remediation

Immediate Action: Update affected Cisco ASA and FTD installations to the following versions: ASA 9.16.4.85, 9.17.1.45, 9.18.4.47, 9.19.1.37, 9.20.3.7, 9.22.1.3, or FTD 7.0.8.1, 7.2.9, 7.4.2.4, 7.6.1 immediately.

Proactive Monitoring: Review VPN access logs for anomalous HTTP request patterns and monitor system integrity for signs of unauthorized root-level process execution.

Compensating Controls: Restrict access to the VPN web interface to known, trusted IP addresses and implement robust multi-factor authentication to limit the utility of compromised credentials.

Exploitation status

Public Exploit Available: Yes, multiple public proofs-of-concept are available via GitHub.

Analyst recommendation

The extreme severity of this vulnerability, combined with its active exploitation by sophisticated adversaries, necessitates immediate remediation. Administrators must prioritize the application of the vendor-provided patches. If patching cannot be performed immediately, the affected VPN services should be isolated or restricted to prevent further exploitation attempts.

More Cisco CVEs

Sources