CVE-2025-20133
Cisco Adaptive Security Appliance (ASA) vulnerability analysis and mitigation

Overview

CVE-2025-20133 is a Denial of Service (DoS) vulnerability in the Remote Access SSL VPN authentication feature of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software. It allows an unauthenticated, remote attacker to cause the affected device to stop responding to Remote Access SSL VPN authentication requests. The vulnerability was discovered internally by Jason Crowder of the Cisco Advanced Security Initiatives Group (ASIG) and publicly disclosed on August 14, 2025. It carries a CVSS v3.1 base score of 8.6 (High) (Cisco Advisory).

Technical details

The vulnerability is classified as CWE-401 (Missing Release of Memory after Effective Lifetime), indicating a memory leak condition triggered during the SSL VPN authentication process. Ineffective validation of user-supplied input to the management and VPN web server endpoints allows an attacker to send a specially crafted HTTP request that causes the device to exhaust resources and stop responding. The attack requires no authentication, no user interaction, and is network-accessible with low complexity, making it straightforward to exploit. Exploitation is contingent on the device having an active SSL listen socket — detectable via show asp table socket | include SSL — which is present when features such as AnyConnect SSL VPN, IKEv2 Remote Access with client services, or the management web server are enabled (Cisco Advisory).

Impact

Successful exploitation causes a targeted DoS condition in which the affected Cisco Secure Firewall device stops responding to Remote Access SSL VPN authentication requests, effectively blocking remote access for all VPN users. The impact is limited to availability — there is no confidentiality or integrity impact — but the scope is marked as Changed, meaning the DoS condition can affect resources beyond the vulnerable component itself. For organizations relying on Cisco ASA or FTD devices as their primary remote access gateway, exploitation could severely disrupt business operations and remote workforce connectivity (Cisco Advisory, Feedly).

Exploitability

As of the time of disclosure, Cisco PSIRT is not aware of any public announcements or malicious use of this vulnerability in the wild, and no public proof-of-concept exploit code is known to exist (Cisco Advisory). The EPSS score is approximately 0.062%, reflecting a currently low probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.

Exploitation steps

  1. Reconnaissance: Identify internet-facing Cisco ASA or FTD devices with Remote Access SSL VPN enabled using tools such as Shodan or Censys, searching for devices exposing HTTPS on ports 443 or 8443 with Cisco ASA/FTD banners.
  2. Confirm vulnerability: Verify the target has an active SSL listen socket by observing SSL/TLS service responses on the VPN web server port, consistent with AnyConnect SSL VPN, IKEv2 with client services, or management web server being enabled.
  3. Craft malicious request: Construct a specially crafted HTTP request targeting the Remote Access SSL VPN authentication endpoint on the device's management or VPN web server.
  4. Send crafted request: Transmit the malicious request to the VPN service port (e.g., TCP 443 or 8443) on the target device without requiring any credentials or prior authentication.
  5. Trigger DoS condition: The ineffective input validation causes a memory leak (CWE-401), leading the device to stop responding to subsequent SSL VPN authentication requests, effectively denying VPN access to all users (Cisco Advisory).

Indicators of compromise

  • Network: Unusual or repeated crafted HTTPS requests to the VPN web server port (TCP 443 or 8443) from unexpected source IPs; sudden cessation of SSL VPN authentication responses from the firewall.
  • Logs: ASA/FTD system logs showing the device becoming unresponsive to VPN authentication requests; memory exhaustion or resource depletion messages in system logs around the time of the incident.
  • Device Behavior: The device stops responding to Remote Access SSL VPN authentication requests while other services may remain partially functional; administrators may observe the device requiring a reload to restore VPN functionality.
  • CLI Indicators: Output of show asp table socket | include SSL showing SSL listen sockets present on affected ports prior to the DoS event; memory utilization metrics showing abnormal growth before the device stops responding (Cisco Advisory).

Mitigation and workarounds

Cisco has released free software updates that address this vulnerability; there are no workarounds available. Administrators should upgrade to a fixed release of Cisco Secure Firewall ASA Software or Secure FTD Software as identified using the Cisco Software Checker tool on the Cisco Security Advisories page. To determine if a device is currently vulnerable, run show asp table socket | include SSL — if SSL listen sockets are present, the device should be treated as vulnerable until patched. As an interim risk-reduction measure, restrict access to the VPN web server to trusted IP ranges where operationally feasible, and monitor VPN authentication logs for anomalous traffic patterns (Cisco Advisory).

Community reactions

The vulnerability was disclosed as part of Cisco's August 2025 Semiannual Cisco Secure Firewall ASA, Secure FMC, and Secure FTD Software Security Advisory Bundled Publication, which also included a separate CVSS 10.0 critical flaw (CVE-2025-20265) in Cisco Secure Firewall Management Center, drawing significant media attention (The Hacker News, BleepingComputer). The CIS issued an advisory noting multiple vulnerabilities in Cisco security products could allow for arbitrary code execution, grouping CVE-2025-20133 within the broader August 2025 Cisco advisory bundle (CIS Advisory). Community and media coverage largely focused on the critical RCE flaw in FMC, with CVE-2025-20133 receiving secondary attention as a high-severity DoS issue affecting widely deployed firewall products.

Additional resources

  • Cisco Advisory — Official Cisco Security Advisory for CVE-2025-20133 and CVE-2025-20243
  • CIS Advisory — CIS Multi-Vulnerability Advisory for August 2025 Cisco Products
  • BleepingComputer — Media Coverage of August 2025 Cisco Firewall Advisories
  • CISA Bulletin — CISA Vulnerability Summary Bulletin Including CVE-2025-20133
  • ZeroPath Summary — Technical Summary of CVE-2025-20133
  • RedHat CVE — Red Hat CVE Entry for CVE-2025-20133
  • ENISA EUVD — ENISA European Vulnerability Database Entry

SourceThis report was generated using AI

Related Cisco Adaptive Security Appliance (ASA) vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-20349HIGH8.6
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:o:cisco:adaptive_security_appliance_software
YesYesAug 11, 2026
CVE-2026-20012HIGH8.6
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:o:cisco:adaptive_security_appliance_software
NoYesMar 25, 2026
CVE-2026-20025MEDIUM6.8
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:o:cisco:adaptive_security_appliance_software
NoYesMar 04, 2026
CVE-2026-20023MEDIUM6.5
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:o:cisco:adaptive_security_appliance_software
NoYesMar 04, 2026
CVE-2026-20024MEDIUM5.7
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:o:cisco:adaptive_security_appliance_software
NoYesMar 04, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management