Too many Cisco ASA firewalls still unsecure despite zero-day attack alerts
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-20333 +1 in the same advisory: …20362 | Authenticated Buffer Overflow RCE in Cisco ASA/FTD VPN Web Server CVE-2025-20333 is a buffer overflow (CWE-120) in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software, caused by improper validation of user-supplied input in HTTP(S) requests. An attacker who already holds valid VPN user credentials can trigger it by sending crafted HTTP(S) requests to the device's VPN web interface; the flaw is remotely exploitable over the network with low attack complexity and no user interaction. A successful exploit allows arbitrary code execution as root, possibly resulting in complete compromise of the firewall or VPN gateway. Any organization running Cisco ASA or FTD software with the VPN web server enabled is affected. Exploitation is confirmed in the wild: the CVE was added to CISA's KEV on 2025-09-25, EPSS assigns a 70.7% probability of exploitation within 30 days (99th percentile), and Cisco and the UK NCSC have warned of real-world attacks (including RayInitiator and LINE VIPER malware deployment) that chain this flaw with at least one companion Cisco vulnerability. Do: Inventory all ASA/FTD devices with the VPN web server reachable by users (especially internet-exposed ones) and upgrade to the fixed releases listed in the Cisco PSIRT advisory; where patching is delayed, apply Cisco's recommended mitigations and hunt for indicators of the reported attack chain (RayInitiator/LINE VIPER). Because exploitation requires valid VPN credentials, treat VPN user credentials on affected gateways as potentially compromised and force resets. US federal agencies must follow the mitigation steps in CISA Emergency Directive 25-03 and BOD 22-01 timelines for this KEV entry. | 9.9 group max | 71% | KEV |
| mass≈100,000–300,000 internet-exposed ASA/FTD VPN web servers (order of magnitude), within a multi-million-device installed base serving large VPN user populations | |
| CVE-2025-20352 | SNMP Stack Buffer Overflow in Cisco IOS and IOS XE Enables DoS and Root RCE Cisco IOS and IOS XE contain a stack-based buffer overflow (CWE-121) in the Simple Network Management Protocol (SNMP) subsystem. An attacker who can reach the device's SNMP service can send crafted SNMP requests: with a low-privileged SNMP account the attacker can crash the device and force a reload (denial of service), while with a high-privileged SNMP account the attacker can execute arbitrary code as root and take full control of the device. Any organization running Cisco IOS or IOS XE on routers, switches, or controllers is potentially affected, especially where SNMP is enabled or reachable from untrusted networks. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2025-09-29, confirming exploitation in the wild, and EPSS assigns it a 39.4% probability of exploitation within 30 days (99th percentile). CVSS scoring is not yet available and no public proof-of-concept is known, but defenders should treat the flaw as actively exploited. Do: Upgrade IOS and IOS XE devices to fixed software releases as specified in Cisco's security advisory; given the KEV listing, federal agencies should follow BOD 22-01 timelines or apply vendor-directed mitigations. As interim mitigation, restrict SNMP access to trusted management hosts using ACLs (and management VRFs where supported), disable SNMP on devices that do not need it, and audit existing SNMP community strings and SNMPv3 users to identify accounts with high privilege levels, which expose the root code-execution path. | 7.7 | 39% | KEV |
| massmillions of installed IOS/IOS XE devices worldwide, with likely hundreds of thousands internet-exposed where SNMP is reachable |
Full article559 words · extracted from helpnetsecurity.com · click to collapse
Despite Cisco and various cybersecurity agencies warning about attackers actively exploting zero-day vulnerabilities (CVE-2025-20333 and CVE-2025-20362) in Cisco Adaptive Security Appliances (ASA) for months, there are still around 48,000 vulnerable appliances out there.
The number is provided by the Shadowserver Foundation, which is scanning for internet-facing vulnerable Cisco ASA/FTD instances every day. A majority of those are located in the US, and the rest mostly in the UK, Japan, Russia, Germany, and Canada.
Surge in Cisco ASA scanning preceded public disclosure of attacks
In May 2025, Cisco was engaged by multiple cybersecurity agencies to support their investigation of attacks targeting government organizations via Cisco ASA 5500-X Series devices.
“Attackers were observed to have exploited multiple zero-day vulnerabilities and employed advanced evasion techniques such as disabling logging, intercepting CLI commands, and intentionally crashing devices to prevent diagnostic analysis,” the company said.
They also noted that the tactics, techniques, and procedures (TTPs) and the custom malware employed by the attackers point to the involvement of the same (suspected state-sponsored) threat actor as the ArcaneDoor attack campaign.
In late August, i.e., several weeks before Cisco and the cybersecurity agencies shared details about the attacks and zero-days exploited, Greynoise detected scanning surges against Cisco ASA devices hitting ASA login portals, IOS Telnet/SSH and ASA software personas. The company warned at the time that future vulnerability disclosures were likely imminent.
Whether these scans were performed by the same threat actor is impossible to tell.
Cisco customers advised to act quickly
What’s sure is that Cisco ASA and FTD appliances are deployed by many government organizations and private sector companies, and they are of high value to all types of attackers.
Organizations should check whether their instances are vulnerable and if they are, check for indicators of compromise and ask Cisco for help if they aren’t sure how to go about it.
The company also advises customers to replace devices that will soon reach their out-of-support dated and update vulnerable devices to a fixed release as soon as possible. Local passwords, certificates, and keys on potentially compromised devices should also be replaced.
“This is best achieved by resetting the device to factory defaults after the upgrade to a fixed release and then reconfiguring the device from scratch with new passwords, and re-generated certificates and keys,” Cisco noted.
Affected organizations should also report any evidence of compromise to the cybersecurity agency in their respective countries.
Organizations that are using Cisco’s routers and switches meant for SMB, enterprise and industrial settings should also upgrade the firmware to fix a bucketload of vulnerabilities, including one (CVE-2025-20352) that has been exploited in zero-day attacks. (There’s currently no indication that these attacks and those targeting ASA devices are performed by the same threat actor.)
UPDATE (November 6, 2025, 07:00 a.m. ET):
Cisco updated the security advisories for CVE-2025-20333 and CVE-2025-20362 to say that, on November 5, 2025, they became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTD Software releases that are affected by the two vulnerabilities.
“This attack can cause unpatched devices to unexpectedly reload, leading to denial of service (DoS) conditions,” they noted, and advised customers to upgrade to a fixed software release.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/10/01/too-many-cisco-asa-firewalls-still-unsecure-despite-zero-day-attack-alerts/