CVE-2025-20271 describes a denial-of-service vulnerability in the Cisco AnyConnect VPN server on Cisco Meraki MX and Z Series Teleworker Gateway devices, stemming from variable initialization errors during SSL VPN session establishment. An unauthenticated, remote attacker can exploit this by sending crafted HTTPS requests, causing the AnyConnect service to restart and disrupting all active VPN sessions. This vulnerability carries a high CVSS score of 8.6, indicating a critical impact where a sustained attack could render the VPN service unavailable. There is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed in CISA's KEV catalog, though it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Cisco | Cisco Meraki MX Firmware | N/ACNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.