PT-2025-39421 · Cisco · Cisco Secure Firewall Asa +1
Published
2025-09-25
·
Updated
2025-09-28
·
CVE-2025-20362
6.5
Medium
Base vector | Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
**Name of the Vulnerable Software and Affected Versions**
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software versions prior to 9.12
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software versions 9.12 and 9.14
**Description**
A flaw exists in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software. This issue is due to a lack of proper authorization checks, allowing an unauthenticated remote attacker to access restricted URL endpoints related to remote access VPN functionality. The attacker exploits this by sending specially crafted HTTP requests to the targeted web server. Reports indicate active exploitation of this issue, with potential compromise of critical infrastructure systems. The Cisco PSIRT is aware of ongoing exploitation attempts. The vulnerability allows access to resources that should require authentication.
**Recommendations**
For versions prior to 9.12, apply the necessary updates to address the authorization issue.
For versions 9.12 and 9.14, install the security patch available on the Cisco software downloads portal.
Fix
Missing Authorization
Weakness Enumeration
Related Identifiers
Affected Products
References · 69
- https://bdu.fstec.ru/vul/2025-11751 · Security Note
- https://nvd.nist.gov/vuln/detail/CVE-2025-20362 · Security Note
- https://sec.cloudapps.cisco.com/security/center/resources/asa_ftd_continued_attacks · Vendor Advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-YROOTUW · Vendor Advisory
- https://reddit.com/r/Cisco/comments/1nr4dcd/whos_working_this_weekend_to_patch_asa_ftd · Reddit Post
- https://twitter.com/DarkWebInformer/status/1971279626778669172 · Twitter Post
- https://twitter.com/cyber_sec_raj/status/1971775806130344330 · Twitter Post
- https://twitter.com/ReliaQuestTR/status/1971617274961207514 · Twitter Post
- https://twitter.com/jgreigj/status/1971286505344860254 · Twitter Post
- https://twitter.com/Horizon3ai/status/1971682685660942766 · Twitter Post
- https://t.me/NeKaspersky/4664 · Telegram Post
- https://twitter.com/GreyNoiseIO/status/1971678958665322579 · Twitter Post
- https://vuldb.com/?id.325890https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-YROOTUW · Note
- https://twitter.com/zoomeye_team/status/1971505370578419746 · Twitter Post
- https://twitter.com/freedomhack101/status/1971929162157117510 · Twitter Post