CVE-2025-20362 is a critical authentication bypass vulnerability in Cisco Secure Firewall ASA and FTD Software, allowing unauthenticated remote attackers to access restricted VPN URL endpoints due to improper input validation. With a CVSS score of 8.6 (High), this vulnerability is easily exploitable over the network with low attack complexity, potentially leading to information disclosure, unauthorized access, and denial-of-service conditions. This flaw is actively exploited in the wild, as confirmed by its inclusion in CISA's KEV catalog, and has garnered significant community attention and media coverage, indicating widespread concern and potential for further exploitation. Cisco strongly recommends immediate upgrades to patched software versions to mitigate the risk of unexpected device reloads and DoS attacks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.12, < 9.12.4.72CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* | ||
>= 9.14, < 9.14.4.28CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* | ||
>= 9.16, < 9.16.4.85CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* | ||
>= 9.17.0, < 9.18.4.67CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* | ||
>= 9.19, < 9.20.4.10CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.