CVE-2025-20362

9.5 CISA KEV

Cisco · Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense

A missing authorization vulnerability in the VPN web server of Cisco ASA and FTD software allows unauthenticated remote attackers to access restricted URL endpoints.

Executive summary

This critical vulnerability in Cisco Secure Firewall products is actively exploited in the wild and allows unauthenticated attackers to bypass authorization controls.

Vulnerability

This is a missing authorization flaw (CWE-862) within the VPN web server component. An unauthenticated, remote attacker can exploit improper input validation in HTTP(S) requests to access restricted URL endpoints that should require authentication.

Business impact

Successful exploitation allows unauthorized access to sensitive VPN-related endpoints, potentially exposing internal network information or facilitating further compromise. Given the 9.5 CVSS score and confirmed active exploitation, this flaw poses a severe risk to organizational infrastructure, including the potential for denial of service conditions or chaining with other vulnerabilities to achieve remote code execution.

Remediation

Immediate Action: Upgrade all affected Cisco ASA and FTD devices to the fixed software releases specified in the official Cisco security advisory.

Proactive Monitoring: Monitor VPN web server logs for suspicious or unauthorized access attempts to restricted URL endpoints.

Compensating Controls: Implement strict ingress filtering and evaluate the use of edge security controls to limit exposure of the VPN web interface until patches are applied.

Exploitation status

Public Exploit Available: Yes, a public Proof-of-Concept repository exists on GitHub.

Analyst recommendation

Due to the critical nature of this vulnerability, its presence in the CISA Known Exploited Vulnerabilities catalog, and confirmed active exploitation, immediate patching is mandatory. Administrators must consult the official Cisco advisory to identify and install the specific fixed software versions for their environment to prevent unauthorized access and potential service disruption.

More Cisco CVEs

Sources