Remote File Manipulation Vulnerability in Cisco Secure Firewall Products
CVE-2025-20251
8.5HIGH
What is CVE-2025-20251?
A vulnerability in the Remote Access SSL VPN service of Cisco Secure Firewall ASA and FTD Software could allow an authenticated remote attacker to manipulate critical system files on the operating system. This could result in the denial of service for new and existing VPN sessions. The issue arises from inadequate input validation in handling HTTP requests, enabling attackers to exploit this by sending specially crafted requests. Affected devices would require a manual reboot to restore normal functionality after an exploit.
Affected Version(s)
Cisco Adaptive Security Appliance (ASA) Software 9.12.3
Cisco Adaptive Security Appliance (ASA) Software 9.8.3
Cisco Adaptive Security Appliance (ASA) Software 9.12.1