LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-20333: Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Buffer Overflow Vulnerability

RBRecent Breaches Vulnerability Intelligence·Sep 25, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Sep 26, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-20333 to its Known Exploited Vulnerabilities catalog on Sep 25, 2025, with a federal patch deadline of Sep 26, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Software VPN Web Server contain a buffer overflow vulnerability that allows for remote code execution…

CVE-2025-20333 is a buffer overflow vulnerability in the VPN Web Server component of Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software. It can allow remote code execution on affected devices. Because these platforms commonly sit at the network edge and terminate remote-access VPN sessions, successful exploitation can give an attacker a foothold on a critical security control. The flaw can also be chained with CVE-2025-20362, increasing the potential impact. Public detail beyond the CISA summary is limited; confirm exact scope against the vendor advisory.

How it works

The vulnerability is classified as CWE-120 (classic buffer overflow). The VPN Web Server fails to properly bound the size of certain input before copying it into a fixed-size memory buffer. An unauthenticated remote attacker who can reach the VPN Web Server can supply oversized or specially crafted data that overwrites adjacent memory. On many systems this can be leveraged to alter control flow and execute arbitrary code with the privileges of the affected process. No public exploit mechanics or payload details are provided in the available facts; defenders should treat any reachable VPN Web Server interface as potentially abusable until the vendor patch is applied. Chaining with CVE-2025-20362 is noted by CISA but the precise interaction is not described here.

Am I affected? How to find it in your systems

Cisco ASA and FTD appliances are typically deployed as perimeter firewalls, VPN concentrators, or next-generation firewalls in data centers and branch offices. The vulnerable component is the VPN Web Server, so any device that has remote-access or clientless VPN features enabled is of primary interest.

If inventory data is incomplete, treat every internet-facing ASA/FTD instance as potentially affected until proven otherwise by version check against the vendor advisory.

How to remediate

Apply the software update published by Cisco for CVE-2025-20333 as the primary remediation. Follow the vendor’s installation and verification steps exactly, including any required reloads or configuration migrations. After patching, re-validate that the VPN Web Server is running the corrected code and that no residual vulnerable images remain in boot variables or standby units.

Federal civilian executive branch agencies must also follow the mitigation steps and timelines in CISA Emergency Directive 25-03 and applicable BOD 22-01 guidance for cloud-hosted instances, or discontinue use if mitigations cannot be applied.

If you can't patch immediately

Until the vendor update can be installed, reduce the attack surface and increase detection capability:

These measures lower risk but do not eliminate it; schedule the official patch as soon as change windows allow.

If your data may have been exposed

Vulnerabilities that enable remote code execution on perimeter firewalls are frequently used as initial access vectors in broader compromises. Although ransomware use of this specific CVE is not documented, any confirmed exploitation should trigger incident-response procedures: isolate the device, preserve logs and memory if possible, hunt for lateral movement, and rotate credentials that traversed the VPN. Organizations can also run a free exposure scan of their email addresses against known breach data sets to determine whether associated accounts have appeared in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCisco · Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense
WeaknessCWE-120
Added to CISA KEVSep 25, 2025
Federal patch deadlineSep 26, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities