Remote File Manipulation Vulnerability in Cisco Secure Firewall Products
CVE-2025-20251

8.5HIGH

Key Information:

Badges

👾 Exploit Exists

What is CVE-2025-20251?

A vulnerability in the Remote Access SSL VPN service of Cisco Secure Firewall ASA and FTD Software could allow an authenticated remote attacker to manipulate critical system files on the operating system. This could result in the denial of service for new and existing VPN sessions. The issue arises from inadequate input validation in handling HTTP requests, enabling attackers to exploit this by sending specially crafted requests. Affected devices would require a manual reboot to restore normal functionality after an exploit.

Affected Version(s)

Cisco Adaptive Security Appliance (ASA) Software 9.12.3

Cisco Adaptive Security Appliance (ASA) Software 9.8.3

Cisco Adaptive Security Appliance (ASA) Software 9.12.1

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.