Remote Access SSL VPN Vulnerability in Cisco Secure Firewall Products
CVE-2025-20133

8.6HIGH

Key Information:

Badges

👾 Exploit Exists

What is CVE-2025-20133?

A vulnerability exists within the Remote Access SSL VPN feature of Cisco Secure Firewall ASA and Secure FTD Software. This issue arises from the inadequate handling of user-provided input during the authentication phase. An unauthenticated, remote attacker could exploit this flaw by sending a specially crafted request to the VPN service. If successful, this could lead to a Denial of Service condition, causing the device to become unresponsive and unable to process additional VPN authentication requests, severely impacting network accessibility and functionality.

Affected Version(s)

Cisco Adaptive Security Appliance (ASA) Software 9.12.3

Cisco Adaptive Security Appliance (ASA) Software 9.8.3

Cisco Adaptive Security Appliance (ASA) Software 9.12.1

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-20133 : Remote Access SSL VPN Vulnerability in Cisco Secure Firewall Products