Description

A vulnerability in the TLS 1.3 implementation for a specific cipher for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software for Cisco Firepower 3100 and 4200 Series devices could allow an authenticated, remote attacker to consume resources that are associated with incoming TLS 1.3 connections, which eventually could cause the device to stop accepting any new SSL/TLS or VPN requests. This vulnerability is due to the implementation of the TLS 1.3 Cipher TLS_CHACHA20_POLY1305_SHA256. An attacker could exploit this vulnerability by sending a large number of TLS 1.3 connections with the specific TLS 1.3 Cipher TLS_CHACHA20_POLY1305_SHA256. A successful exploit could allow the attacker to cause a denial of service (DoS) condition where no new incoming encrypted connections are accepted. The device must be reloaded to clear this condition. Note: These incoming TLS 1.3 connections include both data traffic and user-management traffic. After the device is in the vulnerable state, no new encrypted connections can be accepted.

INFO

Published Date :

2025-08-14T16:28:07.785Z

Last Modified :

2025-09-03T17:39:26.506Z

Source :

cisco
AFFECTED PRODUCTS

The following products are affected by CVE-2025-20127 vulnerability.

Vendors Products
Cisco
  • Adaptive Security Appliance Software
  • Firepower Threat Defense
  • Firepower Threat Defense Software
  • Secure Firewall 3105
  • Secure Firewall 3110
  • Secure Firewall 3120
  • Secure Firewall 3130
  • Secure Firewall 3140
  • Secure Firewall 4215
  • Secure Firewall 4225
  • Secure Firewall 4245
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-20127.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact