
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-20133 is a Denial of Service (DoS) vulnerability in the Remote Access SSL VPN authentication feature of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software. It allows an unauthenticated, remote attacker to cause the affected device to stop responding to Remote Access SSL VPN authentication requests. The vulnerability was discovered internally by Jason Crowder of the Cisco Advanced Security Initiatives Group (ASIG) and publicly disclosed on August 14, 2025. It carries a CVSS v3.1 base score of 8.6 (High) (Cisco Advisory).
The vulnerability is classified as CWE-401 (Missing Release of Memory after Effective Lifetime), indicating a memory leak condition triggered during the SSL VPN authentication process. Ineffective validation of user-supplied input to the management and VPN web server endpoints allows an attacker to send a specially crafted HTTP request that causes the device to exhaust resources and stop responding. The attack requires no authentication, no user interaction, and is network-accessible with low complexity, making it straightforward to exploit. Exploitation is contingent on the device having an active SSL listen socket — detectable via show asp table socket | include SSL — which is present when features such as AnyConnect SSL VPN, IKEv2 Remote Access with client services, or the management web server are enabled (Cisco Advisory).
Successful exploitation causes a targeted DoS condition in which the affected Cisco Secure Firewall device stops responding to Remote Access SSL VPN authentication requests, effectively blocking remote access for all VPN users. The impact is limited to availability — there is no confidentiality or integrity impact — but the scope is marked as Changed, meaning the DoS condition can affect resources beyond the vulnerable component itself. For organizations relying on Cisco ASA or FTD devices as their primary remote access gateway, exploitation could severely disrupt business operations and remote workforce connectivity (Cisco Advisory, Feedly).
As of the time of disclosure, Cisco PSIRT is not aware of any public announcements or malicious use of this vulnerability in the wild, and no public proof-of-concept exploit code is known to exist (Cisco Advisory). The EPSS score is approximately 0.062%, reflecting a currently low probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
show asp table socket | include SSL showing SSL listen sockets present on affected ports prior to the DoS event; memory utilization metrics showing abnormal growth before the device stops responding (Cisco Advisory).Cisco has released free software updates that address this vulnerability; there are no workarounds available. Administrators should upgrade to a fixed release of Cisco Secure Firewall ASA Software or Secure FTD Software as identified using the Cisco Software Checker tool on the Cisco Security Advisories page. To determine if a device is currently vulnerable, run show asp table socket | include SSL — if SSL listen sockets are present, the device should be treated as vulnerable until patched. As an interim risk-reduction measure, restrict access to the VPN web server to trusted IP ranges where operationally feasible, and monitor VPN authentication logs for anomalous traffic patterns (Cisco Advisory).
The vulnerability was disclosed as part of Cisco's August 2025 Semiannual Cisco Secure Firewall ASA, Secure FMC, and Secure FTD Software Security Advisory Bundled Publication, which also included a separate CVSS 10.0 critical flaw (CVE-2025-20265) in Cisco Secure Firewall Management Center, drawing significant media attention (The Hacker News, BleepingComputer). The CIS issued an advisory noting multiple vulnerabilities in Cisco security products could allow for arbitrary code execution, grouping CVE-2025-20133 within the broader August 2025 Cisco advisory bundle (CIS Advisory). Community and media coverage largely focused on the critical RCE flaw in FMC, with CVE-2025-20133 receiving secondary attention as a high-severity DoS issue affecting widely deployed firewall products.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."