← Vulnerability feed

Vulnerability record · CVE-2025-20362 · published 25 September 2025

CVE-2025-20362: Cisco Secure Firewall ASA/FTD VPN web server missing authorization

Cisco · Adaptive Security Appliance Software

The VPN web server in Cisco Secure Firewall ASA and FTD software fails to properly validate user-supplied input in HTTP(S) requests, allowing access to restricted remote-access VPN URL endpoints without authentication. Cisco later reported an attack variant that can also cause unpatched devices to reload, producing denial-of-service conditions. Because these devices sit at the network edge and the flaw is remotely reachable without credentials, it is a serious exposure for unpatched firewalls.

8.6 CVSS 3.1 High CISA KEV since 25 Sep 2025 EPSS 87% · top 0.3% CWE-862 · Missing authorization
8.6CVSS 3.1 base score
87%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
3References
11 Aug 2026Last modified by NVD

Description

Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTD Software releases that are affected by CVE-2025-20333 and CVE-2025-20362. This attack can cause unpatched devices to unexpectedly reload, leading to denial of service (DoS) conditions. Cisco strongly recommends that all customers upgrade to the fixed software releases that are listed in the Fixed Software ["#fs"] section of this advisory. A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to access restricted URL endpoints that are related to remote access VPN that should otherwise be inaccessible without authentication. This vulnerability is due to improper validation of user-supplied input in HTTP(S) requests. An attacker could exploit this vulnerability by sending crafted HTTP requests to a targeted web server on a device. A successful exploit could allow the attacker to access a restricted URL without authentication.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityThe flaw is an unauthenticated, remotely reachable missing-authorization issue in edge firewall VPN services, is listed in CISA KEV, and has a very high EPSS score with a documented DoS attack variant.

What it is

The VPN web server in Cisco Secure Firewall ASA and FTD software fails to properly validate user-supplied input in HTTP(S) requests, allowing access to restricted remote-access VPN URL endpoints without authentication. Cisco later reported an attack variant that can also cause unpatched devices to reload, producing denial-of-service conditions. Because these devices sit at the network edge and the flaw is remotely reachable without credentials, it is a serious exposure for unpatched firewalls.

Impact

An unauthenticated remote attacker can reach restricted VPN-related URL endpoints that should require authentication, and a newer attack variant can force unpatched devices to reload, causing a denial of service. The CVSS vector rates confidentiality and integrity impact as low and availability impact as high.

Attack surface

Reached over the network through crafted HTTP(S) requests sent to the VPN web server on the targeted ASA or FTD device. No authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).

Exploitation

CVE-2025-20362 is listed in CISA KEV with a 2025-09-25 addition date, and EPSS shows a 30-day probability of 0.87085 (99.7th percentile), indicating observed exploitation and high likelihood of further attempts. Cisco references confirm continued attacks against affected ASA and FTD devices.

What to do

  • Upgrade to the fixed ASA and FTD software releases listed in Cisco's advisory Fixed Software section as the primary remediation.
  • If immediate upgrade is not possible, apply the mitigation steps in Cisco's continued-attacks guidance and CISA's Emergency Directive 25-03 guidance, or discontinue use of the affected product.
  • Restrict management and VPN web server access to trusted networks and known source addresses where operationally feasible.
  • Monitor Cisco's advisory and CISA KEV entry for updated guidance, including the November 5, 2025 attack variant.
  • Track patching against the KEV due date and verify all internet-facing ASA/FTD instances are covered.

Detection

  • Inspect HTTP(S) request logs on ASA/FTD VPN web servers for crafted requests targeting restricted remote-access VPN URL endpoints without prior authentication.
  • Alert on unexpected device reloads or restarts of ASA/FTD appliances that cannot be explained by maintenance or power events.
  • Correlate VPN web server access from unusual or untrusted source IPs with requests to endpoints that normally require authentication.
  • Review Cisco advisory and CISA guidance for specific indicators and hunt for the described attack variant against unpatched devices.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-20362 to the Known Exploited Vulnerabilities catalog on 25 September 2025 as "Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Missing Authorization Vulnerability". Required action: The KEV due date refers to the deadline by which FCEB agencies are expected to review and begin implementing the guidance outlined in Emergency Directive (ED) 25-03 (URL listed below in Notes). Agencies must follow the mitigation steps provided by CISA (URL listed below in Notes) and vendor’s instructions (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available. Federal deadline 26 September 2025.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-20362 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.9CVE-2025-20333Cisco ASA and FTD VPN web server buffer overflow allows root RCECisco Secure Firewall ASA and FTD Software fail to properly validate user-supplied input in HTTP(S) requests to the VPN web server, causing a classic…KEVEPSS 71%analysed9.1CVE-2023-20269Cisco ASA and FTD remote access VPN AAA separation flawCisco ASA and FTD remote access VPN features fail to properly separate AAA from the HTTPS management and site-to-site VPN features. An attacker can s…KEVEPSS 25%analysed8.8CVE-2016-6366Cisco ASA SNMP buffer overflow allows remote code executionCisco ASA, PIX and FWSM software through 9.4.2.3 contains a classic buffer overflow (CWE-120) reachable through crafted IPv4 SNMP packets. A remote a…KEVEPSS 88%analysed8.6CVE-2026-20349Cisco ASA and FTD SSL VPN HTTP request handling denial of serviceCisco Secure Firewall ASA and FTD software fail to properly check errors when processing HTTP requests in the Remote Access SSL VPN service. An unaut…KEVEPSS 1.0%analysed8.6CVE-2024-20353Cisco ASA and FTD web server HTTP header parsing DoSCisco ASA and FTD management and VPN web servers fail to fully check errors when parsing an HTTP header, so a crafted request can crash and reload th…KEVEPSS 71%analysed7.8CVE-2016-6367Cisco ASA CLI command injection privilege escalationCisco ASA Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices mishandles invalid CLI commands, allowing command injection (CWE-77).…KEVEPSS 23%analysed7.5CVE-2023-44487HTTP/2 Rapid Reset stream cancellation denial of serviceThe HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. T…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2025-20362), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.