Cisco Secure Firewall Adaptive Security Appliance Software and Secure Firewall Threat Defense Software VPN Web Server Unauthorized Access Vulnerability

🚨 SEVERITY: MEDIUM — CVSS 6.5 Security Advisory

TL;DR 📌

A medium-severity vulnerability has been identified in the VPN web server of Cisco Secure Firewall ASA and FTD Software, allowing unauthenticated remote access to restricted URLs. No workarounds are available, and users are strongly advised to upgrade to fixed software releases.

What happened 🕵️‍♂️

A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated remote attacker to access restricted URL endpoints without authentication. This issue arises from improper validation of user-supplied input in HTTP(S) requests. An attacker could exploit this vulnerability by sending crafted HTTP requests to a targeted web server, potentially gaining access to restricted URLs.

Affected products 🖥️

The vulnerability affects Cisco Secure Firewall ASA and FTD Software running vulnerable releases with specific configurations that enable SSL listen sockets.

Vulnerable Configurations:

  • Cisco Secure Firewall ASA Software:

    • AnyConnect IKEv2 Remote Access
    • Mobile User Security (MUS)
    • SSL VPN
  • Cisco Secure Firewall FTD Software:

    • AnyConnect IKEv2 Remote Access
    • AnyConnect SSL VPN

Fixed software 🔧

Upgrade to the first fixed release in your train (or later):

Release / Product First Fixed Release Notes
1.0 Initial public release.
Cisco Secure Firewall ASA Not specified
Cisco Secure FMC Not specified
Cisco Secure FTD Not specified

Workarounds 🧯

There are no workarounds that address this vulnerability.

Risk in context 🎯

With a CVSS score of 6.5, this vulnerability is rated as Medium severity. The risk is significant as it allows unauthenticated access to restricted resources, which could lead to further exploitation or data exposure. Organizations should prioritize patching to mitigate this risk.

Fast facts ⚡

  • Vulnerability ID: CVE-2025-20362
  • CVSS Score: 6.5 (Medium)
  • Exploitation: Active attempts have been reported.
  • Workarounds: None available.
  • Recommended Action: Upgrade to fixed software.

For leadership 🧭

Executive summary. Cisco ASA and FTD firewalls running VPN services such as AnyConnect or SSL VPN have a flaw in their web server that lets an outsider reach parts of the system meant to be locked down, without logging in. There’s no workaround, so affected units need the vendor’s patch applied as a scheduled but not emergency task.

Why it matters:

  • The flaw sits in the VPN web server component that handles AnyConnect IKEv2, Mobile User Security, and SSL VPN sessions – exactly the interfaces most likely to be reachable from the internet.
  • Exploitation requires no credentials: a crafted HTTP(S) request is enough to reach restricted URL endpoints that should sit behind authentication.
  • Cisco has published no workaround, so devices with SSL listen sockets enabled for these VPN features remain exposed until the firmware is upgraded.
  • Both ASA and FTD software trains are affected, so the exposure can span separate hardware generations and management platforms (including FMC) in the same estate.

Now / Next / Later:

  • Now: Identify every ASA and FTD device with AnyConnect IKEv2, MUS, or SSL VPN enabled and confirm whether its SSL listen socket is reachable from outside the trusted network.
  • Next: Schedule an upgrade of each identified ASA, FTD and associated FMC deployment to the first fixed release for its train during the next maintenance window, since no interim workaround exists.
  • Later: Add VPN web server versions to routine firmware tracking so that firewall software with internet-facing SSL VPN listeners is patched on a defined cycle rather than only in response to individual advisories.