Vulnerability in Cisco Secure Firewall VPN Web Server
CVE-2025-20362

6.5MEDIUM

Key Information:

Badges

👾 Exploit Exists

What is CVE-2025-20362?

A security flaw in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance and Threat Defense Software permits unauthorized remote access to restricted URL endpoints. This vulnerability arises from inadequate validation of user-supplied input in HTTP(S) requests. Attackers can exploit this issue by sending specially crafted HTTP requests to the targeted web server, potentially allowing them access to areas that should require authentication.

Affected Version(s)

Cisco Adaptive Security Appliance (ASA) Software 9.8.1

Cisco Adaptive Security Appliance (ASA) Software 9.8.1.5

Cisco Adaptive Security Appliance (ASA) Software 9.8.1.7

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-20362 : Vulnerability in Cisco Secure Firewall VPN Web Server