VulnCity

Cisco ASA Authorization Bypass

  • شناسه CVE: CVE-2025-20362
  • شدت: بالا
  • امتیاز CVSS: 8.6
  • فروشنده/سازنده: Cisco
Auth BypassCiscoFirewallChain
An authorization bypass vulnerability in Cisco ASA that, when combined with CVE-2025-20333 (VPN RCE), creates a complete attack chain for full appliance compromise.

## Vulnerability Overview
This vulnerability allows an unauthenticated attacker to bypass authorization checks on the management interface of Cisco ASA appliances. The flaw exists in the HTTP request processing logic, where specially crafted URI paths can circumvent access control lists (ACLs) and authentication requirements.

## Technical Details
- **Type:** Improper Authorization (CWE-863)
- **Root Cause:** Path normalization inconsistency between the HTTP parser and the authorization engine. The authorization check uses the raw URI, while the backend handler processes the normalized URI, allowing path traversal-style bypasses.
- **Chain with CVE-2025-20333:** The RCE vulnerability provides initial code execution, and this auth bypass allows the attacker to elevate privileges to administrative level without valid credentials.

## Impact
- Unauthorized access to the management interface
- Read configuration files including VPN credentials and certificates
- When chained with CVE-2025-20333: complete administrative control

## Exploitation
The exploit is straightforward — crafted HTTP requests with path traversal sequences can bypass the authorization engine and access administrative endpoints.

نرم‌افزارهای تحت تأثیر

  • Cisco ASA
  • Cisco FTD