CVE Feed

    Dashboard / CVE / CVE-2025-20127

    CVE-2025-20127

    A vulnerability in the TLS 1.3 implementation for a specific cipher for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software for Cisco Firepower 3100 and 4200 Series devices could allow an authenticated, remote attacker to consume resources that are associated with incoming TLS 1.3 connections, which eventually could cause the device to stop accepting any new SSL/TLS or VPN requests. This vulnerability is due to the implementation of the TLS 1.3 Cipher TLS_CHACHA20_POLY1305_SHA256. An attacker could exploit this vulnerability by sending a large number of TLS 1.3 connections with the specific TLS 1.3 Cipher TLS_CHACHA20_POLY1305_SHA256. A successful exploit could allow the attacker to cause a denial of service (DoS) condition where no new incoming encrypted connections are accepted. The device must be reloaded to clear this condition. Note: These incoming TLS 1.3 connections include both data traffic and user-management traffic. After the device is in the vulnerable state, no new encrypted connections can be accepted.

    Published:Aug 14, 2025
    Last Modified:Aug 11, 2026
    EPS:Aug 14, 2025
    EPSS Score:0.00619
    CVSS Score:7.7

    Affected Products

    Vendor
    Cisco
    Product
    Adaptive Security Appliance Software
    Vendor
    Cisco
    Product
    Firepower Threat Defense Software
    Vendor
    Cisco
    Product
    Secure Firewall 3105
    Vendor
    Cisco
    Product
    Secure Firewall 3110
    Vendor
    Cisco
    Product
    Secure Firewall 3120
    Vendor
    Cisco
    Product
    Secure Firewall 3130
    Vendor
    Cisco
    Product
    Secure Firewall 3140
    Vendor
    Cisco
    Product
    Secure Firewall 4215
    Vendor
    Cisco
    Product
    Secure Firewall 4225
    Vendor
    Cisco
    Product
    Secure Firewall 4245
    Vendor
    Cisco
    Product
    Secure Firewall Threat Defense

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High