216.73.216.233

CVE-2025-20127

· Published 14/08/2025 17:15 · Modified 15/08/2025 13:12

Labels: CVE-2025-20127 2025-08-14CVE-2025-20127CWE-404[email protected]

Essential information

Published
14/08/2025 17:15
Modified
15/08/2025 13:12
Author
Creator
CVSS
7.7 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H

CVSS metrics

Description

A vulnerability in the TLS 1.3 implementation for a specific cipher for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software for Cisco Firepower 3100 and 4200 Series devices could allow an authenticated, remote attacker to consume resources that are associated with incoming TLS 1.3 connections, which eventually could cause the device to stop accepting any new SSL/TLS or VPN requests. This vulnerability is due to the implementation of the TLS 1.3 Cipher TLS_CHACHA20_POLY1305_SHA256. An attacker could exploit this vulnerability by sending a large number of TLS 1.3 connections with the specific TLS 1.3 Cipher TLS_CHACHA20_POLY1305_SHA256. A successful exploit could allow the attacker to cause a denial of service (DoS) condition where no new incoming encrypted connections are accepted. The device must be reloaded to clear this condition. Note: These incoming TLS 1.3 connections include both data traffic and user-management traffic. After the device is in the vulnerable state, no new encrypted connections can be accepted.

NVD status

Status
Undergoing Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
cisco / secure firewall asa cpe:2.3:a:cisco:secure_firewall_asa:*:*:*:*:*:*:*:*
cisco / secure firewall ftd cpe:2.3:a:cisco:secure_firewall_ftd:*:*:*:*:*:*:*:*
cisco / firepower 3100 cpe:2.3:h:cisco:firepower_3100:*:*:*:*:*:*:*:*
cisco / firepower 4200 cpe:2.3:h:cisco:firepower_4200:*:*:*:*:*:*:*:*

References