CVE-2025-20244: Cisco Adaptive Security Appliance ASA Software
High severity, CVSS 7.7. EPSS: 0.5% chance of exploitation in the next 30 days.
A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow a remote attacker that is authenticated as a VPN user to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to incomplete error checking when parsing an HTTP header field value. An attacker could exploit this vulnerability by sending a crafted HTTP request to a targeted Remote Access SSL VPN service on an affected device. A successful exploit could allow the attacker to cause a DoS condition, which would cause the affected device to reload.
Affected products
- Cisco Cisco Adaptive Security Appliance ASA Software: version 9.12.3 only; version 9.8.3 only; version 9.12.1 only; version 9.8.1 only; version 9.12.2 only; version 9.8.2.45 only; …
- Cisco Cisco Firepower Threat Defense Software: version 6.2.3.14 only; version 6.4.0.1 only; version 6.2.3.7 only; version 6.2.3 only; version 6.4.0.2 only; version 6.2.3.9 only; …
Published 2025-08-14. Last modified 2026-06-17.