CVE-2025-20222
published 2025-08-14CVE-2025-20222: A vulnerability in the RADIUS proxy feature for the IPsec VPN feature of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure…
PriorityP352high8.6CVSS 3.1
AVNACLPRNUINSCCNINAH
EPSS
0.61%
45.1th percentile
A vulnerability in the RADIUS proxy feature for the IPsec VPN feature of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
This vulnerability is due to improper processing of IPv6 packets. An attacker could exploit this vulnerability by sending IPv6 packets over an IPsec VPN connection to an affected device. A successful exploit could allow the attacker to trigger a reload of the device, resulting in a DoS condition.
Affected
89 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_firepower_threat_defense_software | — | — |
| cisco | cisco_firepower_threat_defense_software | — | — |
| cisco | cisco_firepower_threat_defense_software | — | — |
| cisco | cisco_firepower_threat_defense_software | — | — |
| cisco | cisco_firepower_threat_defense_software | — | — |
| cisco | cisco_firepower_threat_defense_software | — | — |
| cisco | cisco_firepower_threat_defense_software | — | — |
| cisco | cisco_firepower_threat_defense_software | — | — |
| cisco | cisco_firepower_threat_defense_software | — | — |
| cisco | cisco_firepower_threat_defense_software | — | — |
| cisco | cisco_firepower_threat_defense_software | — | — |
| cisco | cisco_firepower_threat_defense_software | — | — |
| cisco | cisco_firepower_threat_defense_software | — | — |
| cisco | cisco_firepower_threat_defense_software | — | — |
| cisco | cisco_firepower_threat_defense_software | — | — |
| cisco | cisco_firepower_threat_defense_software | — | — |
| cisco | cisco_firepower_threat_defense_software | — | — |
| cisco | cisco_firepower_threat_defense_software | — | — |
| cisco | cisco_firepower_threat_defense_software | — | — |
| cisco | cisco_firepower_threat_defense_software | — | — |
| cisco | cisco_firepower_threat_defense_software | — | — |
| cisco | cisco_firepower_threat_defense_software | — | — |
| cisco | cisco_firepower_threat_defense_software | — | — |
| cisco | cisco_firepower_threat_defense_software | — | — |
| cisco | cisco_firepower_threat_defense_software | — | — |
CVSS provenance
nvdv3.18.6HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
vendor_cisco8.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qwrq-hc6q-9r7j: A vulnerability in the RADIUS proxy feature for the IPsec VPN feature of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Se
ghsa_unreviewed·2025-08-14
CVE-2025-20222 [HIGH] CWE-120 GHSA-qwrq-hc6q-9r7j: A vulnerability in the RADIUS proxy feature for the IPsec VPN feature of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Se
A vulnerability in the RADIUS proxy feature for the IPsec VPN feature of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
This vulnerability is due to improper processing of IPv6 packets. An attacker could exploit this vulnerability by sending IPv6 packets over an IPsec VPN connection to an affected device. A successful exploit could allow the attacker to trigger a reload of the device, resulting in a DoS condition.
Cisco
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software for Firepower 2100 Series IPv6 over IPsec Denial of Service Vulnerability
vendor_cisco·2025-08-14·CVSS 8.6
CVE-2025-20222 [HIGH] CWE-120 Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software for Firepower 2100 Series IPv6 over IPsec Denial of Service Vulnerability
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software for Firepower 2100 Series IPv6 over IPsec Denial of Service Vulnerability
A vulnerability in the RADIUS proxy feature for the IPsec VPN feature of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
This vulnerability is due to improper processing of IPv6 packets. An attacker could exploit this vulnerability by sending IPv6 packets over an IPsec VPN connection to an affected device. A successful exploit could allow the attacker to trigger a reload of the device, resulting in a DoS condition.
Cisco has released software updates that ad
Cisco
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software for Firepower 2100 Series IPv6 over IPsec Denial of Service Vulnerability
vendor_cisco·CVSS 3.1
CVE-2025-20222 Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software for Firepower 2100 Series IPv6 over IPsec Denial of Service Vulnerability
CVE-2025-20222: Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software for Firepower 2100 Series IPv6 over IPsec Denial of Service Vulnerability
A vulnerability in the RADIUS proxy feature for the IPsec VPN feature of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper processing of IPv6 packets. An attacker could exploit this vulnerability by sending IPv6 packets over an IPsec VPN connection to an affected device. A successful exploit could allow the attacker to trigger a reload of the device, resulting in a DoS condition. Cisco has released software up
No detection rules found.
No public exploits indexed.
2025-08-14
Published