Federal agencies given one day to patch exploited Cisco firewall bugs
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-20333 +1 in the same advisory: …20362 | Authenticated Buffer Overflow RCE in Cisco ASA/FTD VPN Web Server CVE-2025-20333 is a buffer overflow (CWE-120) in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software, caused by improper validation of user-supplied input in HTTP(S) requests. An attacker who already holds valid VPN user credentials can trigger it by sending crafted HTTP(S) requests to the device's VPN web interface; the flaw is remotely exploitable over the network with low attack complexity and no user interaction. A successful exploit allows arbitrary code execution as root, possibly resulting in complete compromise of the firewall or VPN gateway. Any organization running Cisco ASA or FTD software with the VPN web server enabled is affected. Exploitation is confirmed in the wild: the CVE was added to CISA's KEV on 2025-09-25, EPSS assigns a 70.7% probability of exploitation within 30 days (99th percentile), and Cisco and the UK NCSC have warned of real-world attacks (including RayInitiator and LINE VIPER malware deployment) that chain this flaw with at least one companion Cisco vulnerability. Do: Inventory all ASA/FTD devices with the VPN web server reachable by users (especially internet-exposed ones) and upgrade to the fixed releases listed in the Cisco PSIRT advisory; where patching is delayed, apply Cisco's recommended mitigations and hunt for indicators of the reported attack chain (RayInitiator/LINE VIPER). Because exploitation requires valid VPN credentials, treat VPN user credentials on affected gateways as potentially compromised and force resets. US federal agencies must follow the mitigation steps in CISA Emergency Directive 25-03 and BOD 22-01 timelines for this KEV entry. | 9.9 group max | 71% | KEV |
| mass≈100,000–300,000 internet-exposed ASA/FTD VPN web servers (order of magnitude), within a multi-million-device installed base serving large VPN user populations |
Full article812 words · extracted from therecord.media · click to collapse
Federal civilian agencies will have to take a range of actions by Friday evening to address flaws affecting Cisco firewall products that are being exploited by “an advanced threat actor.” The Cybersecurity and Infrastructure Security Agency (CISA) released an emergency directive ordering all federal civilian agencies to patch CVE-2025-20333 and CVE-2025-20362 — two vulnerabilities impacting Cisco Adaptive Security Appliances (ASA). CISA Acting Director Madhu Gottumukkala said federal agencies must take “immediate action due to the alarming ease with which a threat actor can exploit these vulnerabilities, maintain persistence on the device, and gain access to a victim’s network.” "The same risks apply to any organizations using these devices. We strongly urge all entities to adopt the actions outlined in this Emergency Directive,” he added. CVE-2025-20333 carries a severity score of 9.9 out of 10 and CVE-2025-20362 has a score of 6.5. Hackers have been seen chaining the two bugs together during attacks, according to CISA. ASA is a popular product line among governments and large businesses because it consolidates several different security tasks into a single appliance. In addition to being firewalls, the appliances also prevent some intrusions, handle spam, conduct antivirus checks and more. Cisco released patches for the bugs on Thursday, and federal civilian agencies have to take a range of actions that include checking if firewall devices have been compromised. “CISA is directing agencies to account for all Cisco ASA and Firepower devices, collect forensics and assess compromise via CISA-provided procedures and tools, disconnect end-of-support devices, and upgrade devices that will remain in service,” CISA said. British and Canadian cybersecurity officials also noted the threat to Cisco firewalls in alerts issued Thursday. Alongside advisories on both vulnerabilities, Cisco published a lengthy study on the attacks, assessing with high confidence that the campaign is tied to the same hackers behind the ArcaneDoor campaign discovered last year. According to CISA, the hackers are sophisticated and have found ways to gain access to ASAs before manipulating devices so that their access persists through reboots and system upgrades. Cisco previously said the ArcaneDoor attacks uncovered last year were part of a campaign by state-sponsored threat actors. At the time, Cisco declined to say what country was behind the incident but Wired, which first reported on the campaign, said sources told them it “appears to be aligned with China's state interests.” Cisco and CISA did not respond to requests for comment about who is behind exploitation of CVE-2025-20333 and CVE-2025-20362 or what kind of organizations are being attacked. Cisco said in its report on the campaign that it worked with multiple government agencies in May 2025 to investigate attacks targeting the ASA 5500-X Series devices running Cisco Secure Firewall ASA Software with VPN web services. The tech giant said it dedicated a specialized team to work on the investigation and eventually discovered a memory corruption bug in the product software. “Attackers were observed to have exploited multiple zero-day vulnerabilities and employed advanced evasion techniques such as disabling logging … and intentionally crashing devices to prevent diagnostic analysis,” Cisco explained. Cisco noted that it has only seen the hackers maintain their access after reboots and software upgrades on ASA 5500-X Series platforms. The company said several of the specific brands impacted include 5585-X — which stopped receiving support on May 31, 2023, as well as 5512-X and 5515-X, which stopped receiving support on August 31, 2022. Support for 5525-X, 5545-X, and 5555-X ends on September 30 this year. Cisco provided troves of advice for customers to follow if they own these devices. If compromises are found or suspected, Cisco said “all configuration elements of the device should be considered untrusted.” “Cisco recommends that all configurations – especially local passwords, certificates, and keys – be replaced after the upgrade to a fixed release,” the company said. “This is best achieved by resetting the device to factory defaults after the upgrade to a fixed release using the configure factory-default command in global configuration mode and then reconfiguring the device with new passwords, certificates, and keys from scratch.” Cisco noted that it worked with CISA and the cybersecurity bureaus of Canada, Australia and the U.K. on the investigation into the bugs. "This is a critical moment for Canadian organizations,” said Rajiv Gupta, head of the Canadian Centre for Cyber Security. “Threat actors are targeting legacy systems with increasing sophistication. I urge all critical infrastructure sectors to act swiftly.” Correction: A previous version of this story incorrectly stated the name of a vulnerability affecting Cisco products. It is CVE-2025-20333, not CVE-2025-30333. 5500-X Series devices
No previous article
No new articles
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/cisco-asa-firewall-bugs-cisa-federal-agencies-warning