
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-20363 is a heap-based buffer overflow (CWE-122) in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software that enables remote code execution. For ASA and FTD, exploitation requires no authentication; for IOS, IOS XE, and IOS XR, a low-privileged authenticated remote attacker is sufficient. The vulnerability was first published on September 25, 2025, and carries a CVSS v3.1 base score of 9.0 (Critical) for ASA/FTD and 8.5 (High) for IOS/IOS XE/IOS XR (Cisco Advisory). Affected ASA versions span multiple release trains (9.12–9.23), FTD versions 7.0–7.7, IOS 12.2(15)b through 15.9(3)m11, IOS XE 3.2.0sg through 17.17.1, and select IOS XR 6.x releases on 32-bit ASR 9001 hardware (Cisco Advisory).
The root cause is improper validation of user-supplied input in HTTP requests processed by the affected web services (CWE-122: Heap-based Buffer Overflow). An attacker exploits this by sending specially crafted HTTP requests to a targeted web service endpoint — specifically when SSL VPN or HTTP server features are enabled — after gathering additional system information or overcoming exploit mitigations (Cisco Advisory). On ASA and FTD, the vulnerable configurations include Mobile User Security (MUS), SSL VPN (webvpn enable), and AnyConnect SSL VPN; on IOS/IOS XE, the Remote Access SSL VPN feature must be active; on IOS XR, the HTTP server must be enabled on 32-bit (QNX-based) ASR 9001 hardware. The attack complexity is rated High, reflecting the need to obtain system information or bypass mitigations before achieving code execution (Cisco Advisory). A technical deep-dive was published by Horizon3.ai covering CVE-2025-20363 alongside related vulnerabilities (Horizon3.ai).
Successful exploitation allows an attacker to execute arbitrary code as root on the affected device, leading to complete device compromise — including full confidentiality, integrity, and availability impact (Cisco Advisory). Because the affected products are perimeter security devices (firewalls, VPN concentrators, and core routers), compromise enables attackers to intercept or manipulate all traffic passing through the device, pivot into protected network segments, and establish persistent footholds. In observed campaigns, threat actors deployed custom malware families (RayInitiator and LINE VIPER) on compromised Cisco ASA devices, enabling long-term espionage and lateral movement across targeted organizations (Cisco Advisory, Talos Blog).
Cisco has released fixed software for all affected product lines and strongly recommends immediate upgrade — there are no workarounds available (Cisco Advisory). Fixed ASA versions include 9.12.4.72, 9.14.4.28, 9.16.4.84, 9.18.4.57, 9.19.1.42, 9.20.3.16, 9.22.2, and 9.23.1.3; fixed FTD versions include 7.0.8, 7.2.10, 7.4.2.3, and 7.7.10. For IOS XR on 32-bit ASR 9001, customers must contact Cisco TAC to request an SMU patch. As interim risk reduction measures, organizations should restrict access to SSL VPN and HTTP server interfaces to trusted IP ranges, disable the HTTP server on IOS XR devices where not required, and deploy Snort rules 65371–65372 released by Cisco. End-of-life ASA 5500-X series devices (5512-X, 5515-X, 5525-X, 5545-X, 5555-X, 5585-X) should be replaced, as UK and US authorities have urged organizations to retire these unsupported appliances (Cisco Advisory, ComputerWeekly).
Cisco issued an official advisory on September 25, 2025, and published a dedicated Event Response page for continued attacks against Cisco firewall platforms, acknowledging the vulnerability was discovered internally during a TAC support case and thanking CISA, UK NCSC, Canadian CCCS, and Australian ASD for supporting the investigation (Cisco Advisory). CISA issued an Emergency Directive ordering U.S. federal agencies to patch, and multiple national CERTs (Canada, Australia, Singapore, EU, Ireland, Belgium) published urgent advisories (CyberScoop, Canadian CCCS). Security researcher Kevin Beaumont (GossiTheDog) was notably active on Mastodon tracking exploitation and scanning activity, and published firmware update tracking data on GitHub (GossiTheDog GitHub). Cloudflare deployed emergency WAF rules, and community discussion on Reddit's r/Cisco reflected widespread urgency among network administrators scrambling to patch over weekends (BleepingComputer, Reddit).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."