Remote Access SSL VPN Vulnerability in Cisco Secure Firewall Products
CVE-2025-20244

7.7HIGH

Key Information:

Badges

👾 Exploit Exists

What is CVE-2025-20244?

A remote access SSL VPN vulnerability exists in Cisco Secure Firewall Adaptive Security Appliance and Threat Defense Software, allowing authenticated users to exploit incomplete error checking in HTTP header parsing. By sending a specially crafted HTTP request, an attacker could force the affected devices to reload unexpectedly, resulting in service disruptions.

Affected Version(s)

Cisco Adaptive Security Appliance (ASA) Software 9.12.3

Cisco Adaptive Security Appliance (ASA) Software 9.8.3

Cisco Adaptive Security Appliance (ASA) Software 9.12.1

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-20244 : Remote Access SSL VPN Vulnerability in Cisco Secure Firewall Products