ZeroHour
The Recordpublished ()ingested

Federal agencies not fully patching vulnerable Cisco devices amid ‘active exploitation,’ CISA warns

criticalAdvisory exploited in the wildimportance 60CVE-2025-20333CVE-2025-20362

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-20333
+1 in the same advisory: …20362
Authenticated Buffer Overflow RCE in Cisco ASA/FTD VPN Web Server

CVE-2025-20333 is a buffer overflow (CWE-120) in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software, caused by improper validation of user-supplied input in HTTP(S) requests. An attacker who already holds valid VPN user credentials can trigger it by sending crafted HTTP(S) requests to the device's VPN web interface; the flaw is remotely exploitable over the network with low attack complexity and no user interaction. A successful exploit allows arbitrary code execution as root, possibly resulting in complete compromise of the firewall or VPN gateway. Any organization running Cisco ASA or FTD software with the VPN web server enabled is affected. Exploitation is confirmed in the wild: the CVE was added to CISA's KEV on 2025-09-25, EPSS assigns a 70.7% probability of exploitation within 30 days (99th percentile), and Cisco and the UK NCSC have warned of real-world attacks (including RayInitiator and LINE VIPER malware deployment) that chain this flaw with at least one companion Cisco vulnerability.

Do: Inventory all ASA/FTD devices with the VPN web server reachable by users (especially internet-exposed ones) and upgrade to the fixed releases listed in the Cisco PSIRT advisory; where patching is delayed, apply Cisco's recommended mitigations and hunt for indicators of the reported attack chain (RayInitiator/LINE VIPER). Because exploitation requires valid VPN credentials, treat VPN user credentials on affected gateways as potentially compromised and force resets. US federal agencies must follow the mitigation steps in CISA Emergency Directive 25-03 and BOD 22-01 timelines for this KEV entry.

9.9
group max
71% KEV
  • Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
  • Cisco Secure Firewall Threat Defense (FTD) Software
mass≈100,000–300,000 internet-exposed ASA/FTD VPN web servers (order of magnitude), within a multi-million-device installed base serving large VPN user populations
Full article629 words · extracted from therecord.media · click to collapse

Federal civilian agencies are not patching vulnerable Cisco devices sufficiently to protect themselves from an exploitation campaign that began in September, the Cybersecurity and Infrastructure Security Agency (CISA) warned Wednesday.

The agency issued an emergency directive in September about two bugs affecting Cisco firewall products that were being exploited by “an advanced threat actor.”

Federal civilian agencies were ordered to report back to CISA about their efforts to mitigate the two vulnerabilities impacting Cisco Adaptive Security Appliances.

OnWednesday, CISA said it has analyzed the data reported by agencies and has “identified devices marked as ‘patched’ in the reporting template, but which were updated to a version of the software that is still vulnerable to the threat activity outlined in the [emergency directive].”

“CISA is tracking active exploitation of these vulnerable versions in [Federal Civilian Executive Branch] agencies,” the directive said. 

CISA provided a detailed list of devices and versions that either have to be updated or switched out for new models. The document covers the minimum software versions that address the vulnerabilities and directs federal agencies to “conduct corrective patching measures on devices that are not compliant with these requirements.”

Any agency that has not already updated to the necessary software version or devices will need to follow new guidance to address “new threat activity.”

CISA did not respond to requests for comment about whether there are federal agencies that have already been breached. 

The release from CISA comes a week after Recorded Future News exclusively reported that Chinese hackers spent much of October scanning for and exploiting the bugs — CVE-2025-20333 and CVE-2025-20362 — at U.S. financial institutions, defense contractors and military organizations.

Incident responders from Palo Alto Networks’ Unit 42 saw scanning and exploitation activity targeting 12 IP addresses used by federal agencies and 11 IP addresses at the local and state government level. 

Government IP addresses in India, Nigeria, Japan, Norway, France, the U.K., the Netherlands, Spain, Australia, Poland, Austria, UAE, Azerbaijan and Bhutan were also targeted.

Unit 42 attributed the targeting of Cisco ASA devices to Storm-1849 — a China-based threat group that Cisco previously said has been attacking the tools since 2024.

The Cisco devices are used widely by governments and large businesses to consolidate several security tasks into a single appliance. In addition to acting as firewalls, the appliances also prevent some intrusions, handle spam, conduct antivirus checks and more.

CISA has not attributed the exploitation of the bugs to a threat actor but said it is linked to the same nation-state hackers behind the ArcaneDoor campaign discovered last year. Researchers and journalists reported previously that the ArcaneDoor campaign was conducted by government hackers based in China. 

Agencies were given just one day to apply the patches and CISA stressed that threat actors were exploiting the bugs with “alarming ease.” Cisco said in its report on the campaign that it worked with multiple government agencies in May 2025 to investigate attacks targeting the ASA 5500-X Series devices running Cisco Secure Firewall ASA Software with VPN web services.

The advisory released by CISA on Wednesday confirmed that hackers have continued to target the devices since its September directive.

“By following these best practices, organizations can better protect themselves from potential threats and ensure the integrity of their digital infrastructure,” said Nick Andersen, executive assistant director for the cybersecurity division  at CISA. “The release of this implementation guidance is a critical step in mitigating the risks posed by these vulnerabilities."

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/federal-cisco-patches-warning