ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

"Patched" but still exposed: US federal agencies must remediate Cisco flaws (again)

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-12480
Improper Access Control in Gladinet Triofox Exploited in the Wild

Gladinet Triofox versions prior to 16.7.10368.56560 contain an improper access control flaw (CWE-284) that leaves the product's initial setup pages reachable without authentication even after initial configuration is complete. Because the flaw requires no privileges, user interaction, or special conditions (CVSS:3.1 AV:N/AC:L/PR:N/UI:N), a remote attacker can reach these setup pages on an internet-reachable Triofox server. By re-entering the setup flow, an attacker can reconfigure the deployment, and public reporting indicates attackers abused this to run malicious payloads via the antivirus configuration feature and install remote access tools, producing high confidentiality and integrity impact (C:H/I:H/A:N). Any organization running an affected Triofox version, whether deployed on-premises or as a cloud service, is exposed. The flaw is being actively exploited: Google/Mandiant published a public technical writeup, CISA added it to the Known Exploited Vulnerabilities catalog on 2025-11-12, and EPSS puts the 30-day exploitation probability at 90.5% (100th percentile).

Do: Upgrade Triofox to version 16.7.10368.56560 or later per vendor instructions; where patching is not immediately possible, apply vendor mitigations, restrict access to the setup pages, and note that federal agencies must follow CISA BOD 22-01 guidance (including for cloud services) or discontinue use. Given confirmed in-the-wild exploitation, check for compromise: review the antivirus configuration for tampering, hunt for installed remote access tools or unexpected payloads, and audit accounts and configuration changes made after initial setup.

9.191% KEV PoC
  • Gladinet Triofox prior to 16.7.10368.56560
moderateorder of a few thousand internet-facing Triofox deployments (est.), plausibly serving tens of thousands of users
CVE-2025-20333
+1 in the same advisory: …20362
Authenticated Buffer Overflow RCE in Cisco ASA/FTD VPN Web Server

CVE-2025-20333 is a buffer overflow (CWE-120) in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software, caused by improper validation of user-supplied input in HTTP(S) requests. An attacker who already holds valid VPN user credentials can trigger it by sending crafted HTTP(S) requests to the device's VPN web interface; the flaw is remotely exploitable over the network with low attack complexity and no user interaction. A successful exploit allows arbitrary code execution as root, possibly resulting in complete compromise of the firewall or VPN gateway. Any organization running Cisco ASA or FTD software with the VPN web server enabled is affected. Exploitation is confirmed in the wild: the CVE was added to CISA's KEV on 2025-09-25, EPSS assigns a 70.7% probability of exploitation within 30 days (99th percentile), and Cisco and the UK NCSC have warned of real-world attacks (including RayInitiator and LINE VIPER malware deployment) that chain this flaw with at least one companion Cisco vulnerability.

Do: Inventory all ASA/FTD devices with the VPN web server reachable by users (especially internet-exposed ones) and upgrade to the fixed releases listed in the Cisco PSIRT advisory; where patching is delayed, apply Cisco's recommended mitigations and hunt for indicators of the reported attack chain (RayInitiator/LINE VIPER). Because exploitation requires valid VPN credentials, treat VPN user credentials on affected gateways as potentially compromised and force resets. US federal agencies must follow the mitigation steps in CISA Emergency Directive 25-03 and BOD 22-01 timelines for this KEV entry.

9.9
group max
71% KEV
  • Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
  • Cisco Secure Firewall Threat Defense (FTD) Software
mass≈100,000–300,000 internet-exposed ASA/FTD VPN web servers (order of magnitude), within a multi-million-device installed base serving large VPN user populations
CVE-2025-62215
Local Privilege Escalation via Race Condition in Microsoft Windows Kernel

A race condition (improper synchronization of concurrent access to shared resources, tracked alongside a double-free issue, CWE-362/CWE-415) in the Microsoft Windows Kernel allows an authenticated local attacker to elevate privileges. To trigger it, an attacker with low privileges must run code that races kernel operations on a shared resource; the high attack complexity means timing must line up, but successful races corrupt kernel state and yield elevated execution. A successful exploit grants the attacker kernel/SYSTEM-level access with high impact on confidentiality, integrity, and availability of the host. All Windows 10 builds from 1809 through 22H2, Windows 11 23H2 through 25H2, and Windows Server 2019 through 2025 are affected. Microsoft patched the flaw in its November 2025 Patch Tuesday release, and CISA added it to the Known Exploited Vulnerabilities catalog on 2025-11-12 as actively exploited in the wild; no public PoC is known and ransomware use is unconfirmed.

Do: Apply Microsoft's November 2025 Patch Tuesday security updates for every affected Windows 10, Windows 11, and Windows Server version, prioritizing servers, domain controllers, and multi-user hosts where local privilege escalation has the greatest downstream impact. Because the flaw requires only low local privileges, treat any unpatched system where untrusted users or malware can execute code (RDS/VDI, kiosks, developer workstations) as at risk, and US federal agencies must remediate per CISA BOD 22-01 timelines. After deployment, verify the OS build reflects the November 2025 update, as active exploitation is confirmed even though no public PoC is available.

7.06% KEV
  • microsoft Windows 10 1809 (builds prior to the November 2025 security updates)
  • microsoft Windows 10 21H2 (builds prior to the November 2025 security updates)
  • microsoft Windows 10 22H2 (builds prior to the November 2025 security updates)
  • +7 more
masshundreds of millions of Windows endpoints and servers (essentially every supported Windows 10/11 desktop and Windows Server 2019+ host worldwide)
CVE-2025-9242
Out-of-Bounds Write in WatchGuard Fireware OS iked Enables Unauthenticated RCE

WatchGuard Fireware OS contains an out-of-bounds write (CWE-787) in the iked process that a remote, unauthenticated attacker can trigger to execute arbitrary code on the appliance. The flaw is reachable via the mobile user VPN with IKEv2 and via branch office VPNs using IKEv2 to a dynamic gateway peer; devices whose IKEv2 configurations were deleted may remain vulnerable if a branch office VPN to a static gateway peer is still configured. Successful exploitation yields full system compromise, reflected in the CVSS v4.0 base score of 9.3 (network vector, no privileges or user interaction, high impact on confidentiality, integrity and availability). WatchGuard Firebox appliances with IKEv2 VPN services are affected, with public reporting citing roughly 54,000 internet-exposed Fireboxes; the issue was added to CISA's Known Exploited Vulnerabilities catalog on 2025-11-12, a public proof-of-concept exploit exists, and headlines indicate use in ransomware attacks (KEV ransomware field is listed as unknown). EPSS assigns a 91.3% probability of exploitation within 30 days (100th percentile), so remediation urgency is high.

Do: Apply the patched Fireware OS release per WatchGuard's security advisory immediately (exact fixed version numbers are not provided in the source data); the KEV listing makes BOD 22-01 remediation timelines mandatory for U.S. federal agencies. As an interim mitigation, restrict or disable IKEv2 VPN exposure — mobile user VPN with IKEv2 and branch office VPN IKEv2, including residual static-peer BOVPN configurations on devices that previously had IKEv2 configured — to trusted sources only. Administrators should audit configuration history to identify Fireboxes with prior IKEv2 mobile VPN or dynamic-peer BOVPN setups, since these may remain vulnerable even after the configs were deleted.

9.391% KEV PoC
  • WatchGuard Firebox appliances running Fireware OS (iked process)
large≈54,000 internet-exposed Fireboxes (public scan figure cited in coverage)
Full article467 words · extracted from helpnetsecurity.com · click to collapse

CISA has ordered US federal agencies to fully address two actively exploited vulnerabilities (CVE-2025-20333, CVE-2025-20362) in Cisco Adaptive Security Appliances (ASA) and Firepower firewalls.

“In CISA’s analysis of agency-reported data, CISA has identified devices marked as ‘patched’ in the reporting template, but which were updated to a version of the software that is still vulnerable to the threat activity outlined in [Emergency Directive 25-03, released on September 25, 2025],” the agency stated on Wednesday.

“CISA is tracking active exploitation of these vulnerable versions in [Federal Civilian Executive Branch] agencies. For agencies with ASA or Firepower devices not yet updated to the necessary software versions or devices that were updated after September 26, 2025, CISA recommends additional actions to mitigate against ongoing and new threat activity.”

Last week, Cisco updated the two vulnerabilities’ advisories to say that they became aware of a new attack variant leveraging them.

CVE-2025-20333 and CVE-2025-20362

CVE-2025-20333, which allows for remote code execution, and CVE-2025-20362, which makes privilege escalation possible, have been spotted being exploited as zero-days earlier this year.

In late September, CISA and several other cybersecurity agencies warned about the attacks and attributed them to a state-sponsored threat actor that perpetrated the ArcaneDoor attack campaign in 2023 and 2024.

Those attacks also involved the use of zero-day flaws. The threat actor used custom malware to disable logging and prevent the creation of a crash dump, and modified the ROMMON program that runs before the ASA operating system to assure the persistence of a custom backdoor they installed.

Completing the vulnerabilities’ mitigation

The Shadowserver Foundation noted in early October that despite repeated warnings, they could still detect around 48,000 unpatched internet-facing appliances, predominantly in the US. That number has since fallen to a little over 32,000.

All ASA and Firepower devices, not just those that are public-facing, have to be updated to a firmware version that fixes both, CISA pointed out. Legacy/unsupported devices must be decommissioned and swapped with newer, up-to-date ones.

“If CISA has identified an agency with this issue, we will follow up to confirm that these actions have been taken,” the agency added.

The new guidance lists firmware versions required to mitigate both vulnerabilities.

CISA has also added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on the same day and directed US FCEB agencies to address them by December 3, 2025.

Those include:

  • CVE-2025-12480, affecting the Gladinet Triofox secure file sharing and remote access platform
  • CVE-2025-62215, the Windows Kernel fixed by Microsoft this Patch Tuesday, and
  • CVE-2025-9242, a critical pre-auth RCE flaw in WatchGuard’s Firebox network security appliances that’s been patched in September and confirmed to be under active exploitation on October 21.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/11/13/cisa-directive-cve-2025-20333-cve-2025-20362/