CVE-2025-20263
A vulnerability in the web services interface of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an affected system. This vulnerability is due to insufficient boundary checks for specific data that is provided to the web services interface of an affected system. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected system. A successful exploit could allow the attacker to cause a buffer overflow condition on the affected system, which could cause the system to reload, resulting in a denial of service (DoS) condition.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.6
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
- EPSS probability
- 0.65%
- CWE
- CWE-680
- Published
- 2025-08-14
- Last modified
- 2026-03-12
Affected products
- Cisco Cisco Adaptive Security Appliance (ASA) Software
- Cisco Cisco Adaptive Security Appliance (ASA) Software
- Cisco Cisco Adaptive Security Appliance (ASA) Software
- Cisco Cisco Adaptive Security Appliance (ASA) Software
- Cisco Cisco Adaptive Security Appliance (ASA) Software
- Cisco Cisco Adaptive Security Appliance (ASA) Software
- Cisco Cisco Adaptive Security Appliance (ASA) Software
- Cisco Cisco Adaptive Security Appliance (ASA) Software
Weakness type
Related vulnerabilities
- CVE-2026-81647 — Out-of-bounds read vulnerability in the graphics module....
- CVE-2026-19313 — Fireware OS Pre-Authentication Heap Buffer Overflow in iked Allows Remote Code Execution
- CVE-2026-70651 — libvips: Possible integer overflow when reading multi-page TIFF images via ImageMagick
- CVE-2026-19588 — Integer Overflow to Buffer Overflow vulnerability in Samsung Open Source rlottie allows Overflow...
- CVE-2026-43627 — llama.cpp b1283–b9058 Integer Overflow in llama_batch_init() Function
- CVE-2026-55200 — libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c
- CVE-2026-8376 — Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds
- CVE-2026-24928 — Out-of-bounds write vulnerability in the file system module....