cbcvebase.
CVE-2025-20362
published 2025-09-25

CVE-2025-20362: Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTD Software releases…

PriorityP193high8.6CVSS 3.1
AVNACLPRNUINSUCLILAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2025-09-26
Exploited in the wild
EPSS
85.54%
99.7th percentile
Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTD Software releases that are affected by CVE-2025-20333 and CVE-2025-20362. This attack can cause unpatched devices to unexpectedly reload, leading to denial of service (DoS) conditions. Cisco strongly recommends that all customers upgrade to the fixed software releases that are listed in the Fixed Software ["#fs"] section of this advisory. A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to access restricted URL endpoints that are related to remote access VPN that should otherwise be inaccessible without authentication. This vulnerability is due to improper validation of user-supplied input in HTTP(S) requests. An attacker could exploit this vulnerability by sending crafted HTTP requests to a targeted web server on a device. A successful exploit could allow the attacker to access a restricted URL without authentication.

Affected

13 ranges
VendorProductVersion rangeFixed in
ciscoadaptive_security_appliance_software>= 9.12 < 9.12.4.729.12.4.72
ciscoadaptive_security_appliance_software>= 9.14 < 9.14.4.289.14.4.28
ciscoadaptive_security_appliance_software>= 9.16 < 9.16.4.859.16.4.85
ciscoadaptive_security_appliance_software>= 9.17.0 < 9.18.4.679.18.4.67
ciscoadaptive_security_appliance_software>= 9.19 < 9.20.4.109.20.4.10
ciscoadaptive_security_appliance_software>= 9.22 < 9.22.2.149.22.2.14
ciscoadaptive_security_appliance_software>= 9.23 < 9.23.1.199.23.1.19
ciscofirepower_threat_defense>= 7.0.0 < 7.0.8.17.0.8.1
ciscofirepower_threat_defense>= 7.1.0 < 7.2.10.27.2.10.2
ciscofirepower_threat_defense>= 7.3.0 < 7.4.2.47.4.2.4
ciscofirepower_threat_defense>= 7.6.0 < 7.6.2.17.6.2.1
ciscofirepower_threat_defense>= 7.7.0 < 7.7.10.17.7.10.1
ciscosecure_firewall_adaptive_security_appliance

Detection & IOCsextracted from sources · hover to see the quote

otherLINE VIPER
otherRayInitiator
sigma
dataset = cisco_asa_raw | alter alert_level = arrayindex(regextract(_raw_log, "\s%.*?(ASA\-[\d])\-[\d]{1,}\:"), 0)
  • CVE-2025-20362 is exploited by sending crafted HTTP(S) requests to the VPN web server to access restricted URL endpoints related to remote access VPN without authentication; monitor for unauthenticated access to VPN-related URL endpoints on Cisco ASA/FTD devices.
  • Threat actor modified ROMMON (ROM Monitor) on compromised Cisco ASA devices to achieve persistence across reboots and software upgrades; forensic analysis should include ROMMON integrity verification.
  • LINE VIPER communicates C2 instructions over WebVPN client authentication sessions over HTTPS and also via ICMP with responses over raw TCP; monitor for anomalous ICMP and raw TCP traffic from Cisco ASA 5500-X devices.
  • Attacks specifically targeted Cisco ASA 5500-X Series devices with VPN web services enabled and without secure boot; prioritize monitoring and patching of this device class.
  • CVE-2025-20362 chained with CVE-2025-20333 enables unauthenticated remote code execution; detect exploitation attempts by correlating unauthenticated VPN URL access (CVE-2025-20362) with subsequent RCE activity (CVE-2025-20333).
  • A new attack variant (disclosed November 5, 2025) against CVE-2025-20333 and CVE-2025-20362 causes unpatched devices to unexpectedly reload (DoS); monitor for unexpected reloads of Cisco ASA/FTD devices as a potential exploitation indicator.
  • ·CVE-2025-20362 is only exploitable when VPN web services (SSL/TLS-based WebVPN) are enabled on the Cisco ASA or FTD device; Cisco's temporary mitigation of disabling SSL/TLS-based VPN web services carries its own operational risks.
  • ·RayInitiator GRUB bootkit and LINE VIPER shellcode loader are specifically deployed to Cisco ASA 5500-X series devices that do NOT have secure boot enabled; devices with secure boot are not susceptible to this persistence mechanism.
  • ·End-of-support Cisco ASA devices cannot receive patches and must be permanently disconnected per CISA Emergency Directive 25-03; patching is not an option for these devices.

CVSS provenance

nvdv3.18.6HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
vulncheck9.9CRITICAL
cisa9.9CRITICAL
vendor_cisco9.9CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.