Remote Access SSL VPN Vulnerability in Cisco Secure Firewall Products
CVE-2025-20244
7.7HIGH
What is CVE-2025-20244?
A remote access SSL VPN vulnerability exists in Cisco Secure Firewall Adaptive Security Appliance and Threat Defense Software, allowing authenticated users to exploit incomplete error checking in HTTP header parsing. By sending a specially crafted HTTP request, an attacker could force the affected devices to reload unexpectedly, resulting in service disruptions.
Affected Version(s)
Cisco Adaptive Security Appliance (ASA) Software 9.12.3
Cisco Adaptive Security Appliance (ASA) Software 9.8.3
Cisco Adaptive Security Appliance (ASA) Software 9.12.1