CVE-2025-20362: Missing Authorization Vulnerability in Cisco ASA/FTD VPN Web Services

ISGroup Cybersecurity

CVE-2025-20362 affects Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software that have VPN web server (WebVPN) services enabled. The vulnerability resides in the VPN web services component and is caused by a lack of authorization checks. By sending specially crafted HTTP(S) requests, an unauthenticated, remote attacker can access restricted URL endpoints that should normally require authentication. This flaw has been actively exploited in targeted campaigns against Cisco edge devices and has been added to CISA’s Known Exploited Vulnerabilities (KEV) Catalog under Emergency Directive ED 25-03, which requires U.S. federal agencies to identify and mitigate affected systems.

ProductCisco ASA
Date2025-09-29 13:09:26
Information
  • Fix Available
  • Active Exploitation

Technical Summary

This is a missing authorization vulnerability (CWE-862) with a CVSS v3.1 base score of 6.5 (Medium). The flaw allows an unauthenticated remote attacker to bypass authorization checks on Cisco ASA/FTD devices with WebVPN services enabled.

If exploited, attackers can gain unauthorized access to sensitive endpoints or functionality, providing an entry point for further attacks such as information disclosure or the exploitation of additional vulnerabilities for deeper compromise.

According to Cisco and various security research reports, this vulnerability has been actively exploited in the wild as part of advanced threat campaigns (notably linked to UAT4356 / Storm-1849) against Cisco ASA and FTD devices. Attackers combine this flaw with other zero-day vulnerabilities (e.g., CVE-2025-20333) to gain persistent and hidden access.

Recommendations

  1. Immediate patching required: Upgrade to the Cisco ASA/FTD software versions that contain the fix for CVE-2025-20362 as soon as possible. Cisco has released corrective updates for all affected branches.

  2. Limit exposure: Disable or restrict access to VPN Web Services / WebVPN components from untrusted networks if the patch cannot be applied immediately.

  3. Network segmentation and access controls: Implement strict network segmentation, review access policies for management interfaces, and restrict exposure of administration consoles to internal networks.

  4. Monitoring and threat hunting: Actively monitor VPN web server logs and network traffic for suspicious or unauthorized access attempts. Follow Cisco and CISA guidelines to identify any potential compromises.

  5. Incident response readiness: If a compromise is suspected, perform forensic analysis on the device, rotate credentials, and follow the remediation steps published by Cisco for compromised ASA/FTD devices.

Protect your organisation with Threat Intelligence and Digital Risk Protection.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert