ZeroHour
The Recordpublished ()ingested

Cisco must share more information about effects of severe bugs on businesses, senator says

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-20333
+1 in the same advisory: …20362
Authenticated Buffer Overflow RCE in Cisco ASA/FTD VPN Web Server

CVE-2025-20333 is a buffer overflow (CWE-120) in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software, caused by improper validation of user-supplied input in HTTP(S) requests. An attacker who already holds valid VPN user credentials can trigger it by sending crafted HTTP(S) requests to the device's VPN web interface; the flaw is remotely exploitable over the network with low attack complexity and no user interaction. A successful exploit allows arbitrary code execution as root, possibly resulting in complete compromise of the firewall or VPN gateway. Any organization running Cisco ASA or FTD software with the VPN web server enabled is affected. Exploitation is confirmed in the wild: the CVE was added to CISA's KEV on 2025-09-25, EPSS assigns a 70.7% probability of exploitation within 30 days (99th percentile), and Cisco and the UK NCSC have warned of real-world attacks (including RayInitiator and LINE VIPER malware deployment) that chain this flaw with at least one companion Cisco vulnerability.

Do: Inventory all ASA/FTD devices with the VPN web server reachable by users (especially internet-exposed ones) and upgrade to the fixed releases listed in the Cisco PSIRT advisory; where patching is delayed, apply Cisco's recommended mitigations and hunt for indicators of the reported attack chain (RayInitiator/LINE VIPER). Because exploitation requires valid VPN credentials, treat VPN user credentials on affected gateways as potentially compromised and force resets. US federal agencies must follow the mitigation steps in CISA Emergency Directive 25-03 and BOD 22-01 timelines for this KEV entry.

9.9
group max
71% KEV
  • Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
  • Cisco Secure Firewall Threat Defense (FTD) Software
mass≈100,000–300,000 internet-exposed ASA/FTD VPN web servers (order of magnitude), within a multi-million-device installed base serving large VPN user populations
Full article596 words · extracted from therecord.media · click to collapse

Technology company Cisco is being asked to answer a series of questions about a security incident that prompted emergency directives from the federal government last month.

U.S. Sen. Bill Cassidy wrote to Cisco CEO Chuck Robbins about CVE-2025-20333 and CVE-2025-20362, vulnerabilities that caused alarm three weeks ago when federal civilian agencies were given just one day to address them

Cassidy, chairman of the Committee on Health, Education, Labor, and Pensions, noted reports that “at least one federal agency has already been breached as a result of this vulnerability.”

“As the largest provider of network infrastructure in the world, Cisco holds a unique position in delivering tools not only to the federal government, but virtually all businesses. These tools connect consumers and businesses to care services, educational tools, and platforms businesses need to operate,” the Louisiana Republican wrote

“Any vulnerability in Cisco’s systems would jeopardize this access for millions of Americans. As Cisco works with the federal government to patch any cybersecurity vulnerabilities, it must work with these stakeholders to ensure their systems are protected as well.”

Cassidy asked whether Cisco has identified any specific threats to customers, how it is communicating security issues to customers, whether the advice provided by CISA to federal agencies also applies to private companies, and more. 

Cisco did not respond to requests for comment. 

On September 25, the Cybersecurity and Infrastructure Security Agency (CISA) released an emergency directive ordering all federal civilian agencies to patch the two vulnerabilities, which impact Cisco Adaptive Security Appliances (ASA).

ASA is a popular product line among governments and large businesses because it consolidates several different security tasks into a single appliance. In addition to being firewalls, the appliances also prevent some intrusions, handle spam, conduct antivirus checks and more. 

Cisco said in its report on the campaign that it worked with multiple government agencies in May 2025 to investigate attacks targeting the ASA 5500-X Series devices running Cisco Secure Firewall ASA Software with VPN web services.

The company said several of the specific brands impacted include 5585-X — which stopped receiving support on May 31, 2023, as well as 5512-X and 5515-X, which stopped receiving support on August 31, 2022. Support for 5525-X, 5545-X, and 5555-X ends on September 30 this year. 

British and Canadian cybersecurity officials also noted the threat to Cisco firewalls in alerts. Cisco said it worked with CISA and the cybersecurity bureaus of Canada, Australia and the U.K. on the investigation into the bugs. 

Alongside advisories on both vulnerabilities, Cisco published a lengthy study on the attacks, assessing with high confidence that the campaign was tied to the same hackers behind the ArcaneDoor campaign discovered last year

Since then,Cisco has declined to say what country was behind the incident. Wired, which first reported on the campaign, said sources claimed it “appears to be aligned with China's state interests.”CISA Acting Director Madhu Gottumukkala said that federal agencies needed to take “immediate action due to the alarming ease with which a threat actor can exploit these vulnerabilities, maintain persistence on the device, and gain access to a victim’s network.”

"The same risks apply to any organizations using these devices. We strongly urge all entities to adopt the actions outlined in this Emergency Directive,” he added.

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/cisco-asa-vulnerabilities-sen-bill-cassidy-questions