Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access VPN Web Server Denial of Service Vulnerability

🚨SEVERITY: HIGH — CVSS 7.7Security Advisory

TL;DR 📌

  • A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow a remote attacker that is authenticated as a VPN user to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability…
  • Highest CVSS: 7.7 (High).
  • Check the advisory for fixed releases — remediation detail is in the vendor link below.
  • CVEs: CVE-2025-20244.

What it is

CVE-2025-20244 affects the Remote Access SSL VPN service in Cisco Secure Firewall ASA Software and Secure FTD Software. The flaw sits in the web server component that handles Remote Access VPN sessions, and is caused by incomplete error checking when parsing an HTTP header field value.

Exploitation requires an attacker who is already authenticated as a VPN user. From that position, they can send a crafted HTTP request to the targeted Remote Access SSL VPN service, which triggers a reload of the affected device — a denial of service condition rather than any code execution or data exposure.

The advisory sets out which configurations expose the vulnerable SSL listen sockets. On ASA, this includes AnyConnect IKEv2 Remote Access with client services, Mobile User Security (MUS, vulnerable only from IP addresses in the configured access hosts), and SSL VPN. On FTD, it includes AnyConnect IKEv2 Remote Access with client services and AnyConnect SSL VPN, both of which are enabled via Remote Access VPN configuration in FMC or FDM. Cisco has confirmed that Secure FMC Software itself is not affected.

This advisory is part of Cisco’s August 2025 semiannual bundled publication for ASA, FMC and FTD software.

What to do

  • Identify any ASA or FTD devices running Remote Access SSL VPN, AnyConnect IKEv2 Remote Access with client services, or (on ASA) Mobile User Security — these are the configurations that expose the vulnerable SSL listen sockets.
  • Apply the Cisco-supplied software updates for your platform; there are no workarounds for this issue, so patching is the only mitigation. For FTD 7.4, Cisco has published hotfixes (e.g. Cisco_FTD_Hotfix_EI-7.4.2.4-2.sh.REL.tar and platform-specific variants for FP1K, FP2K, FP3K, SSP and the Secure FW 4200) — consult the advisory’s fixed software section for the full list matched to your specific release and platform.
  • For MUS on ASA, note the exposure is limited to IP addresses in the configured access hosts list; review that list as part of your assessment, though this does not replace patching.
  • Since exploitation requires an authenticated VPN user, review who holds valid VPN credentials and treat this as a risk from any user or compromised credential on the VPN, not just external unauthenticated traffic.
  • Use the Cisco Secure Firewall ASA Compatibility guide, ASA Upgrade Guide, or Secure Firewall Threat Defense Compatibility Guide to confirm the correct target release for your environment before upgrading.

For leadership 🧭

Executive summary. Any user with valid VPN credentials on an affected Cisco ASA or FTD firewall can force the device to reload by sending it a malformed HTTP request, cutting off remote access for everyone until it recovers. There is no workaround, so this needs to move into a patching cycle rather than sit on a watchlist.

Why it matters:

  • Any authenticated VPN user — not just administrators — can trigger the crash, so a single compromised remote-access credential is enough to take down the firewall’s VPN service.
  • The affected firewall is often the sole path for remote staff and site-to-site connectivity, so a reload disrupts business access, not just a background service.
  • No workaround exists; the only fix is a software update or hotfix, which means exposure persists on unpatched devices until they’re upgraded.
  • Multiple common configurations are exposed: AnyConnect IKEv2 with client services, SSL VPN on ASA, Mobile User Security, and AnyConnect SSL VPN on FTD — most production remote-access setups fall into one of these.

Now / Next / Later:

  • Now: Check which ASA and FTD devices have Remote Access SSL VPN, AnyConnect IKEv2 with client services, or Mobile User Security enabled, since these are the configurations with vulnerable SSL listen sockets.
  • Next: Schedule and apply the Cisco software update or hotfix appropriate to your platform and release (e.g. the FTD 7.4 hotfixes listed in the advisory) during your next change window, as there is no workaround to buy time.
  • Later: Review who holds valid VPN credentials on these firewalls and tighten MUS access-host lists where used, so a single stolen or misused login cannot be leveraged to disrupt the remote-access service again.

Source