CVE-2025-20251
published 2025-08-14CVE-2025-20251: A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat…
PriorityP355high8.5CVSS 3.1
AVNACLPRLUINSCCNILAH
EPSS
0.44%
35.4th percentile
A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker to create or delete arbitrary files on the underlying operating system. If critical system files are manipulated, new Remote Access SSL VPN sessions could be denied and existing sessions could be dropped, causing a denial of service (DoS) condition. An exploited device requires a manual reboot to recover.
This vulnerability is due to insufficient input validation when processing HTTP requests. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to create or delete files on the underlying operating system, which could cause the Remote Access SSL VPN service to become unresponsive.
To exploit this vulnerability, the attacker must be authenticated as a VPN user of the affected device.
Affected
318 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_adaptive_security_appliance_software | — | — |
| cisco | cisco_adaptive_security_appliance_software | — | — |
| cisco | cisco_adaptive_security_appliance_software | — | — |
| cisco | cisco_adaptive_security_appliance_software | — | — |
| cisco | cisco_adaptive_security_appliance_software | — | — |
| cisco | cisco_adaptive_security_appliance_software | — | — |
| cisco | cisco_adaptive_security_appliance_software | — | — |
| cisco | cisco_adaptive_security_appliance_software | — | — |
| cisco | cisco_adaptive_security_appliance_software | — | — |
| cisco | cisco_adaptive_security_appliance_software | — | — |
| cisco | cisco_adaptive_security_appliance_software | — | — |
| cisco | cisco_adaptive_security_appliance_software | — | — |
| cisco | cisco_adaptive_security_appliance_software | — | — |
| cisco | cisco_adaptive_security_appliance_software | — | — |
| cisco | cisco_adaptive_security_appliance_software | — | — |
| cisco | cisco_adaptive_security_appliance_software | — | — |
| cisco | cisco_adaptive_security_appliance_software | — | — |
| cisco | cisco_adaptive_security_appliance_software | — | — |
| cisco | cisco_adaptive_security_appliance_software | — | — |
| cisco | cisco_adaptive_security_appliance_software | — | — |
| cisco | cisco_adaptive_security_appliance_software | — | — |
| cisco | cisco_adaptive_security_appliance_software | — | — |
| cisco | cisco_adaptive_security_appliance_software | — | — |
| cisco | cisco_adaptive_security_appliance_software | — | — |
| cisco | cisco_adaptive_security_appliance_software | — | — |
CVSS provenance
nvdv3.18.5HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H
vendor_cisco8.5HIGH
vendor_msrc5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software VPN Web Server Denial of Service Vulnerability
vendor_cisco·2025-08-14·CVSS 8.5
CVE-2025-20251 [HIGH] CWE-1287 Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software VPN Web Server Denial of Service Vulnerability
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software VPN Web Server Denial of Service Vulnerability
A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker to create or delete arbitrary files on the underlying operating system. If critical system files are manipulated, new Remote Access SSL VPN sessions could be denied and existing sessions could be dropped, causing a denial of service (DoS) condition. An exploited device requires a manual reboot to recover.
This vulnerability is due to insufficient input validation when processing HTTP requests. An attacker could exploit this vulne
Microsoft
A flaw was found in samba. A race condition in the password lockout code may lead to the risk of brute force attacks being successful if special conditions are met.
vendor_msrc·2023-03-14·CVSS 5.9
CVE-2021-20251 [MEDIUM] CWE-362 A flaw was found in samba. A race condition in the password lockout code may lead to the risk of brute force attacks being successful if special conditions are met.
A flaw was found in samba. A race condition in the password lockout code may lead to the risk of brute force attacks being successful if special conditions are met.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mari
Cisco
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software VPN Web Server Denial of Service Vulnerability
vendor_cisco·CVSS 3.1
CVE-2025-20251 Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software VPN Web Server Denial of Service Vulnerability
CVE-2025-20251: Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software VPN Web Server Denial of Service Vulnerability
A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker to create or delete arbitrary files on the underlying operating system. If critical system files are manipulated, new Remote Access SSL VPN sessions could be denied and existing sessions could be dropped, causing a denial of service (DoS) condition. An exploited device requires a manual reboot to recover. This vulnerability is due to insufficient input validation when processing HTTP requests. An attacker could expl
GHSA
GHSA-62cp-qvq6-cfw4: A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Th
ghsa_unreviewed·2025-08-14
CVE-2025-20251 [HIGH] CWE-1287 GHSA-62cp-qvq6-cfw4: A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Th
A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker to create or delete arbitrary files on the underlying operating system. If critical system files are manipulated, new Remote Access SSL VPN sessions could be denied and existing sessions could be dropped, causing a denial of service (DoS) condition. An exploited device requires a manual reboot to recover.
This vulnerability is due to insufficient input validation when processing HTTP requests. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to create or delete files on th
No detection rules found.
No public exploits indexed.
2025-08-14
Published