<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.appian.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>KB-2352 Information about the Cisco Adaptive Security Appliance vulnerability (CVE-2025-20333 and CVE-2025-20362)</title><link>https://community.appian.com/support/w/kb/3712/kb-2352-information-about-the-cisco-adaptive-security-appliance-vulnerability-cve-2025-20333-and-cve-2025-20362</link><description /><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>KB-2352 Information about the Cisco Adaptive Security Appliance vulnerability (CVE-2025-20333 and CVE-2025-20362)</title><link>https://community.appian.com/support/w/kb/3712/kb-2352-information-about-the-cisco-adaptive-security-appliance-vulnerability-cve-2025-20333-and-cve-2025-20362</link><pubDate>Tue, 30 Sep 2025 18:05:54 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:871ec260-a925-4913-bb17-bd54a366b802</guid><dc:creator>pauline.delacruz</dc:creator><comments>https://community.appian.com/support/w/kb/3712/kb-2352-information-about-the-cisco-adaptive-security-appliance-vulnerability-cve-2025-20333-and-cve-2025-20362#comments</comments><description>Current Revision posted to Appian Knowledge Base by pauline.delacruz on 9/30/2025 6:05:54 PM&lt;br /&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;On 25-Sep-2025, Cisco released a &lt;/span&gt;&lt;a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-z5xP8EUB"&gt;&lt;span style="font-weight:400;"&gt;security advisory&lt;/span&gt;&lt;/a&gt;&lt;span style="font-weight:400;"&gt; regarding a vulnerability within the VPN web server for their Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) products. On 29-Sep-2025, CISA released an &lt;/span&gt;&lt;a href="https://industrialcyber.co/cisa/cisa-issues-emergency-directive-requiring-federal-agencies-to-mitigate-critical-cisco-asa-zero-day-vulnerabilities/"&gt;&lt;span style="font-weight:400;"&gt;Emergency Directive&lt;/span&gt;&lt;/a&gt;&lt;span style="font-weight:400;"&gt; requiring all federal agencies and contractors to identify and mitigate the vulnerabilities identified in the advisory.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Appian has investigated these vulnerabilities and services and determined that it is not impacted, as we do not use Cisco ASA or FTD services. We will continue to monitor the situation and provide any updates as appropriate.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="font-weight:400;"&gt;Additional Notes:&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;The following CVEs were released with additional information on the scope of the vulnerability:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/cve-2025-20333"&gt;&lt;span style="font-weight:400;"&gt;CVE-2025-20333&lt;/span&gt;&lt;/a&gt;&lt;span style="font-weight:400;"&gt; - (Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Buffer Overflow Vulnerability)&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/cve-2025-20362"&gt;&lt;span style="font-weight:400;"&gt;CVE-2025-20362&lt;/span&gt;&lt;/a&gt;&lt;span style="font-weight:400;"&gt; - (Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Missing Authorization Vulnerability)&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Supporting Documentation:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-z5xP8EUB"&gt;&lt;span style="font-weight:400;"&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-z5xP8EUB&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://industrialcyber.co/cisa/cisa-issues-emergency-directive-requiring-federal-agencies-to-mitigate-critical-cisco-asa-zero-day-vulnerabilities/"&gt;&lt;span style="font-weight:400;"&gt;https://industrialcyber.co/cisa/cisa-issues-emergency-directive-requiring-federal-agencies-to-mitigate-critical-cisco-asa-zero-day-vulnerabilities/&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;span&gt;Affected Versions&lt;/span&gt;&lt;span style="font-weight:400;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;This article applies to all supported versions of Appian.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Last reviewed: &lt;/span&gt;&lt;span style="font-weight:400;"&gt;Sep 29, 2025&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;
</description></item></channel></rss>