CVE record
CVE-2025-20362
Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Missing Authorization Vulnerability
Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Software VPN Web Server contain a missing authorization vulnerability. This vulnerability could be chained with CVE-2025-20333.
CVE evidence
Known exploitation
Listed in CISA KEV
Absence from the fetched catalog does not establish that exploitation has not occurred.
Severity
unknown
No parseable CVSS vector returned
Affected packages
0
Supported package records returned by OSV. Vendor and product names are not used to infer matches.
CISA Known Exploited Vulnerabilities
Catalog record
- Vendor / project
- Cisco
- Product
- Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense
- Date added
- Sep 25, 2025
- CISA federal remediation due date
- Sep 26, 2025
- Required action
- The KEV due date refers to the deadline by which FCEB agencies are expected to review and begin implementing the guidance outlined in Emergency Directive (ED) 25-03 (URL listed below in Notes). Agencies must follow the mitigation steps provided by CISA (URL listed below in Notes) and vendor’s instructions (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.
- Known ransomware campaign use
- Unknown
- CWE
- CWE-862
OSV package mapping
Affected open-source packages
OSV did not return a package mapping in the five supported ecosystems. RequestGuard does not infer package names from the CISA vendor or product fields.