SB2025090339 - Remote denial of service in Cisco ASA and FTD
Published: September 3, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper resource shutdown or release (CVE-ID: CVE-2025-20127)
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to incorrect implementation of the TLS 1.3 Cipher TLS_CHACHA20_POLY1305_SHA256. A remote user can force the device to stop accepting any new SSL/TLS or VPN requests, leading to a denial of service.
Remediation
Install update from vendor's website.