VulnCity

Cisco ASA/FTD VPN RCE

  • شناسه CVE: CVE-2025-20333
  • شدت: بحرانی
  • امتیاز CVSS: 9.8
  • فروشنده/سازنده: Cisco
RCECiscoFirewallVPNCritical
A critical stack-based buffer overflow vulnerability in the SSL/IKEv2 VPN service of Cisco ASA and FTD firewalls allows unauthenticated remote code execution.

## Vulnerability Overview
This vulnerability exists in the VPN web services module of Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) software. An unauthenticated, remote attacker can exploit this vulnerability by sending crafted SSL/TLS or IKEv2 packets to the VPN interface, resulting in arbitrary code execution with root privileges.

## Technical Details
- **Type:** Stack-based Buffer Overflow (CWE-121)
- **Vulnerable Service:** SSL VPN (WebVPN) and IKEv2 daemon
- **Root Cause:** Improper validation of the length field in the ClientHello TLS extension during SSL VPN negotiation. A specially crafted extension with an oversized length value overflows a fixed-size stack buffer.
- **Exploit Chain:** Often chained with CVE-2025-20362 (Authorization Bypass) for complete attack. The RCE provides initial access, and the auth bypass allows persistent administrative control.

## Impact
- Complete compromise of the firewall appliance
- Access to all VPN traffic (decrypt, intercept, modify)
- Pivot point to the entire internal network
- Ability to modify firewall rules to allow further attacks
- Persistence through firmware modification

## Affected Versions
- Cisco ASA Software 9.16.x – 9.20.x (before security patches)
- Cisco FTD Software 7.2.x – 7.4.x (before hotfix)

نرم‌افزارهای تحت تأثیر

  • Cisco ASA
  • Cisco FTD
  • Cisco Firepower