vendor-advisorystandardsNewsThe Broadside2 min read

Cisco advisory bundles critical RCE bugs across five product lines

FMC, ASA, FTD, ISE, and IOS/IOS XE are all in play, and Cisco won't say which configurations trigger the worst of it, leaving defenders to assume the broadest exposure.


TL;DR

Cisco dropped a multi-product advisory disclosing critical vulnerabilities across its Secure Firewall Management Center, ASA, Firewall Threat Defense, Identity Services Engine, and IOS/IOS XE platforms. The most severe (CVE-2025-20265 in the FMC RADIUS subsystem) allows unauthenticated remote attackers to inject shell commands that execute on-device. No active exploitation reported, but the configuration-dependent nature of the vulnerabilities means organizations can't rely on version checks alone to confirm exposure. Defense contractors and DIB firms running Cisco as their network backbone should treat this as an all-hands configuration review.

Cisco's August 15 advisory isn't a single-product patch notice. It's a cross-portfolio event, bundling critical remote code execution vulnerabilities across five product lines that together cover the perimeter, access control, and core routing layers of the enterprise stack. For the defense industrial base (where Cisco ASA, FTD, and ISE form the connective tissue between classified and unclassified environments) the blast radius is unusually wide.

The lead vulnerability, CVE-2025-20265, sits in the RADIUS subsystem of Cisco Secure Firewall Management Center Software. An unauthenticated, remote attacker can inject arbitrary shell commands that execute on the device. No authentication required, no user interaction. That's the kind of vulnerability that turns a management console into a beachhead if the management interface is reachable, and in practice, FMC often sits on networks with broader exposure than the firewalls it manages.

Cisco's advisory notes that affected systems "are not limited to specific versions" and that impact "is contingent upon certain configuration criteria being met" [1]. But the company didn't specify which configurations trigger the vulnerability. That's the operational problem. Without that detail, security teams can't narrow the scope through config review, they have to assume worst-case exposure across every affected box until they can patch or verify.

The advisory also covers a dozen lower-severity flaws, including multiple denial-of-service conditions in the IKEv2 implementation spanning IOS, IOS XE, ASA, and FTD (CVE-2025-20224 through -20254). A TLS 1.3 cipher bug on Firepower 3100 and 4200 Series hardware can consume connection resources until the device stops accepting new SSL/TLS or VPN requests (CVE-2025-20127). And CVE-2025-20268 allows geolocation-based VPN access policies to be bypassed on FTD, the kind of flaw that quietly undercuts perimeter controls without triggering alerts.

What the practitioner does Monday

If you run Cisco in a regulated environment (CMMC, DFARS, FedRAMP) start with inventory. Identify every FMC, ASA, FTD, ISE, and IOS/IOS XE device in your boundary, regardless of version. Review Cisco's linked configuration details per product; the advisory itself doesn't do the triage for you. Prioritize FMC remediation first: an unauthenticated RCE on the management plane is the worst case in this bundle, and it doesn't require proximity or credentials.

No patch timelines were included in the MS-ISAC advisory, and Cisco's own advisory board framed impact around configuration rather than version cutoffs. That means defenders are in the familiar position of hunting for exposure without a clean yes/no from the vendor. The good news: no active exploitation yet. The bad news: that window doesn't stay open long when the attack surface is this broad.


Published ·Deep Fathom