Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Network Address Translation DNS Inspection Denial of Service Vulnerability

🚨 SEVERITY: HIGH — CVSS 8.6 Security Advisory

TL;DR 📌

A high-severity vulnerability has been identified in Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Software, specifically affecting the Network Address Translation (NAT) DNS inspection feature. An unauthenticated remote attacker could exploit this vulnerability to cause a denial of service (DoS) condition by sending crafted DNS packets. Cisco has released software updates to address this issue, but no workarounds are available.

What happened 🕵️‍♂️

A vulnerability exists in the DNS inspection function for NAT configurations in Cisco Secure Firewall ASA and FTD Software. This flaw allows an unauthenticated remote attacker to send specially crafted DNS packets that trigger an infinite loop, causing the device to reload unexpectedly and resulting in a denial of service (DoS) condition. The vulnerability is due to the processing of DNS packets when DNS inspection is enabled and NAT is configured.

Affected products 🖥️

  • Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
  • Cisco Secure Firewall Threat Defense (FTD) Software

Devices running these software versions with both NAT and DNS inspection features enabled are vulnerable.

Fixed software 🔧

Upgrade to the first fixed release in your train (or later):

Release / Product First Fixed Release Notes
1.0 Initial public release.

Workarounds 🧯

There are no workarounds available to mitigate this vulnerability.

Risk in context 🎯

The vulnerability has a CVSS score of 8.6, categorizing it as High severity. The primary exposure driver is that the vulnerability can be exploited remotely without authentication, leading to potential service disruption. Given the lack of workarounds, immediate patching is essential to mitigate the risk.

Fast facts ⚡

  • Vulnerability ID: CVE-2025-20136
  • CVSS Score: 8.6 (High)
  • Impact: Denial of Service (DoS)
  • Exploitation: Requires crafted DNS packets
  • Workarounds: None available

For leadership 🧭

Executive summary. Firewalls running Cisco ASA or FTD with NAT and DNS inspection enabled can be forced offline remotely by anyone able to send them DNS traffic, with no authentication required and no workaround available. Given the perimeter role these devices typically play, this should be scheduled for patching as an urgent, near-term change.

Why it matters:

  • The flaw sits in the NAT DNS inspection path, so any ASA or FTD device with both NAT and DNS inspection enabled is exposed, not just a niche configuration.
  • Exploitation requires no credentials and only crafted DNS packets, meaning attack complexity is low and the trigger can be reached over the network.
  • The result is an infinite loop that forces the device to reload, taking down firewall and NAT services for whatever traffic depends on it.
  • Cisco has published no workaround, so the only mitigation is disabling DNS inspection (with its own operational trade-offs) or upgrading the software.

Now / Next / Later:

  • Now: Identify every ASA and FTD device where NAT is configured with DNS inspection enabled and treat those as priority patch targets.
  • Next: During the next change window, upgrade affected devices to the first fixed release in their respective train as published in Cisco’s advisory.
  • Later: Review whether DNS inspection is actually required on each firewall’s NAT policy and disable it where not needed, reducing exposure to future flaws in this inspection path.