
⚠ HIGH PRIORITY — CISA KEV. CVE-2025-20362 is a remote code execution vulnerability in Cisco ASA and FTD WebVPN / remote access VPN services. Critical for perimeter firewalls protecting Linux and Windows internal networks.
Affected Cisco
- ASA software trains listed in Cisco PSIRT advisory (2025)
- FTD with remote access VPN / SSL VPN enabled
- Internet-exposed VPN portals on port 443
Verify exposure
show version | include Software
show running-config webvpn
show vpn-sessiondb summaryPatching Method
- Download fixed ASA/FTD image from Cisco Software Central.
- Export running config backup before upgrade.
- Install fixed image via ASDM or CLI
software installworkflow. - Reboot appliance; verify WebVPN service after patch.
- Temporarily disable WebVPN if emergency patch window delayed.
- Review VPN logs for anomalous pre-auth connections.
show version
show running-config | include webvpn
show logging | include 443Post-patch
- Restrict VPN portal source IPs at upstream firewall
- Enable MFA for all VPN users
- Audit for unknown local accounts on ASA