CVE-2025-20333 — Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Buffer Overflow Vulnerability
CVE-2025-20333: Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Buffer Overflow Vulnerability
CISA Known Exploited Vulnerability (KEV)
| Vendor / project | Cisco |
| Product | Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense |
| Date added | 2025-09-25 |
| Due date | 2025-09-26 |
| Ransomware campaign use | Unknown |
Description
Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Software VPN Web Server contain a buffer overflow vulnerability that allows for remote code execution. This vulnerability could be chained with CVE-2025-20362.
Required action (CISA)
The KEV due date refers to the deadline by which FCEB agencies are expected to review and begin implementing the guidance outlined in Emergency Directive (ED) 25-03 (URL listed below in Notes). Agencies must follow the mitigation steps provided by CISA (URL listed below in Notes) and vendor’s instructions (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.
Notes
CISA Mitigation Instructions: https://www.cisa.gov/news-events/directives/ed-25-03-identify-and-mitigate-potential-compromise-cisco-devices ; https://www.cisa.gov/news-events/directives/supplemental-direction-ed-25-03-core-dump-and-hunt-instructions ; https://www.cisa.gov/eviction-strategies-tool/create-from-template ; https://sec.cloudapps.cisco.com/security/center/resources/asa_ftd_continued_attacks ; https://sec.cloudapps.cisco.com/security/center/private/resources/asa_ftd_continued_attacks#Details ; https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-z5xP8EUB ; https://nvd.nist.gov/vuln/detail/CVE-2025-20333
Weakness behind it
CISA records this vulnerability as an instance of CWE-120. From there the chain continues into CAPEC attack patterns and ATT&CK techniques, all inside this corpus.
References
- NVD: https://nvd.nist.gov/vuln/detail/CVE-2025-20333
- KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
See all 1,745 pages under Vulnerabilities (CVE) →
Related pages
Browse by topic
Every page in the corpus, grouped. Search finds one page; this shows what else is here.