CVE-2025-20212
CVSS 3.1 Score 7.7 of 10 (high)
Details
Summary
CVE-2025-20212 is a denial-of-service vulnerability affecting the Cisco AnyConnect VPN server on Cisco Meraki MX and Z Series devices. An authenticated attacker with valid VPN user credentials can exploit this issue by providing crafted attributes during SSL VPN session establishment. The vulnerability arises due to an uninitialized variable, leading to a server restart and failure of established SSL VPN sessions. This results in remote users needing to reinitiate VPN connections and reauthenticate. Persistent attacks can prevent new SSL VPN connections from being established. Upon cessation of the attack traffic, the Cisco AnyConnect VPN server recovers automatically.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Cisco Meraki MX
Affected Vendors
- Cisco