Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software VPN Web Server Denial of Service Vulnerability

🚨 SEVERITY: HIGH — CVSS 8.5 Security Advisory

TL;DR 📌

A high-severity vulnerability has been identified in the Remote Access SSL VPN service of Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Software. This flaw could allow an authenticated attacker to create or delete files on the underlying operating system, potentially leading to a denial of service (DoS) condition. Cisco has released software updates to address this issue, and there are no available workarounds.

What happened 🕵️‍♂️

A vulnerability exists in the Remote Access SSL VPN service for Cisco Secure Firewall ASA and FTD Software due to insufficient input validation when processing HTTP requests. An authenticated attacker could exploit this vulnerability by sending crafted HTTP requests, allowing them to create or delete arbitrary files on the operating system. If critical system files are manipulated, it could result in new VPN sessions being denied and existing sessions being dropped, necessitating a manual reboot of the affected device to recover.

Affected products 🖥️

  • Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
  • Cisco Secure Firewall Threat Defense (FTD) Software

Fixed software 🔧

Upgrade to the first fixed release in your train (or later):

Release / Product First Fixed Release Notes
1.0 Initial public release.

Workarounds 🧯

There are no workarounds that address this vulnerability.

Risk in context 🎯

The vulnerability has a CVSS score of 8.5, indicating a high severity risk. It requires authentication as a VPN user, which limits exposure but still poses a significant risk if exploited. Organizations should prioritize applying the available software updates to mitigate this risk.

Fast facts ⚡

  • Vulnerability ID: CVE-2025-20251
  • CVSS Score: 8.5 (High)
  • Impact: Denial of Service (DoS)
  • Authentication Required: Yes (authenticated VPN user)
  • Exploitation: No public exploitation reported yet

For leadership 🧭

Executive summary. A flaw in the Remote Access SSL VPN component of Cisco ASA and FTD lets someone who already has valid VPN credentials tamper with files on the firewall’s operating system, which can knock out VPN access entirely and require a manual reboot to fix. Given the high severity score and the lack of any workaround, this should be scheduled into the next available change window rather than left until a routine patch cycle.

Why it matters:

  • The Remote Access SSL VPN web server on ASA and FTD accepts crafted HTTP requests from any authenticated VPN user, not just administrators, lowering the bar for someone to trigger the issue.
  • File creation or deletion on the underlying OS can corrupt critical system files, causing new VPN sessions to be refused and existing sessions to drop.
  • Recovery is not automatic: Cisco states the affected device needs a manual reboot to restore normal operation, meaning an outage until someone intervenes.
  • There is no workaround, so firewalls remain exposed to this VPN-facing attack path until the software is upgraded.

Now / Next / Later:

  • Now: Identify every ASA and FTD device running the Remote Access SSL VPN service and check its software train against Cisco’s fixed release table for CVE-2025-20251.
  • Next: Schedule an upgrade to the first fixed release for each affected ASA or FTD train during the next change window, since no workaround exists to reduce exposure in the meantime.
  • Later: Build Cisco ASA/FTD patch tracking into routine firewall maintenance cycles so fixes for VPN-facing services are applied promptly rather than waiting for the next scheduled review.