Denial of Service Vulnerability in Cisco Secure Firewall Adaptive Security Appliance
CVE-2025-20222

8.6HIGH

Key Information:

Vendor

Cisco

Vendor
CVE Published:
14 August 2025

Badges

👾 Exploit Exists

What is CVE-2025-20222?

A vulnerability exists within the RADIUS proxy feature related to the IPsec VPN implementation in Cisco Secure Firewall products. This issue stems from deficient handling of IPv6 packets, which can be exploited by an unauthenticated remote attacker. By sending malformed IPv6 packets through an IPsec VPN connection, the attacker may trigger a device reload, ultimately leading to a denial of service condition that disrupts operations.

Affected Version(s)

Cisco Firepower Threat Defense Software 6.2.3

Cisco Firepower Threat Defense Software 6.2.3.9

Cisco Firepower Threat Defense Software 6.2.3.1

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-20222 : Denial of Service Vulnerability in Cisco Secure Firewall Adaptive Security Appliance