Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software for Firepower 2100 Series IPv6 over IPsec Denial of Service Vulnerability
TL;DR π
- A vulnerability in the RADIUS proxy feature for the IPsec VPN feature of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper processing of IPv6 packets. An attackerβ¦
- Highest CVSS: 8.6 (High).
- Check the advisory for fixed releases β remediation detail is in the vendor link below.
- CVEs: CVE-2025-20222.
What it is
CVE-2025-20222 affects the RADIUS proxy feature for IPsec VPN in Cisco Secure Firewall ASA Software and Secure FTD Software, specifically on Firepower 2100 Series firewalls. The flaw is in how the affected code processes IPv6 packets.
An unauthenticated remote attacker can reach the flaw by sending IPv6 packets over an established IPsec VPN connection to an affected device. No credentials are required. The vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H β network-based, low complexity, no privileges or user interaction needed, scope changed, with high impact on availability and none on confidentiality or integrity. Successful exploitation triggers a device reload, causing a denial of service.
Three conditions must all be true for a device to be exposed: IPsec VPN with IKEv1 or IKEv2 enabled; IPv6 enabled on the interface receiving RADIUS traffic; and, on ASA releases 9.16 and earlier or FTD releases 7.0 and earlier only, an access control list configured on the control plane to permit IP traffic. Cisco has published CLI commands in the advisory to check each of these (show running-config crypto ikev1/ikev2, show running-config interface for IPv6, and show running-config access-group / show access-list for the control-plane ACL condition).
Cisco Secure Firewall Management Center is confirmed not affected, and ASA/FTD running on platforms other than Firepower 2100 Series are also confirmed not vulnerable.
What to do
- Check whether your Firepower 2100 Series devices meet all three conditions above (IKEv1/IKEv2 enabled, IPv6 enabled on the RADIUS-facing interface, and β on older ASA 9.16/FTD 7.0 and earlier β a permissive control-plane ACL). If none apply, the device is not affected.
- There are no workarounds. The only remediation is to install the fixed software; consult the advisory’s Fixed Software section and the Cisco Software Checker for the specific release that resolves this issue for your platform and train.
- This advisory is part of Cisco’s August 2025 bundled ASA/FMC/FTD publication β check the linked event response for other advisories in the same bundle that may affect the same devices, so upgrades can be planned together.
- No public exploitation has been reported by Cisco PSIRT for this issue.
For leadership π§
Executive summary. Firepower 2100 Series firewalls running IPsec VPN with IPv6 enabled on the RADIUS-facing interface can be knocked offline remotely with no credentials required, causing a full device reload. There is no workaround, so remediation depends entirely on scheduling the software upgrade before this reaches a change window.
Why it matters:
- The flaw sits in the RADIUS proxy path for IPsec VPN on Firepower 2100 Series devices, so any exposed VPN endpoint with IPv6 enabled is a live attack surface for an unauthenticated remote attacker.
- A successful trigger forces the appliance to reload, meaning a denial-of-service outage for every VPN session and any traffic passing through that firewall, not just the RADIUS function.
- On older ASA 9.16/FTD 7.0 or earlier builds, a permissive control-plane ACL widens exposure further, so legacy configurations carried forward during upgrades are more likely to qualify.
- With no workaround available, the only path to remediation is a software upgrade, so devices left unpatched remain exposed indefinitely.
Now / Next / Later:
- Now: Run the advisory’s CLI checks (show running-config crypto ikev1/ikev2, show running-config interface for IPv6, and show running-config access-group/access-list for the control-plane ACL) against every Firepower 2100 Series device to confirm which ones meet all three exposure conditions.
- Next: Schedule and apply the fixed ASA or FTD software release identified via the Cisco Software Checker for each affected Firepower 2100 Series device, since no workaround exists to buy time.
- Later: Fold this fix into the same maintenance window as the other advisories in the August 2025 ASA/FMC/FTD bundle so Firepower 2100 Series devices are brought to a consistent, current release rather than patched piecemeal.