By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: CISA instructs federal agencies to patch new flaws in Cisco firewall devices – News
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > News > CISA instructs federal agencies to patch new flaws in Cisco firewall devices – News
News

CISA instructs federal agencies to patch new flaws in Cisco firewall devices – News

News Room
Last updated: 2025/09/27 at 10:47 PM
News Room Published 27 September 2025
Share
SHARE

The U.S. Cybersecurity and Infrastructure Security Agency has instructed federal agencies to patch two zero-day or unpatched vulnerabilities that affect certain Cisco Systems Inc. devices. 

CISA officials issued the directive on Thursday. The zero-day vulnerabilities in question, CVE-2025-20362 and CVE-2025-20333, affect some systems in Cisco’s ASA 5500-X Series family of firewall appliances. The company provides support and updates for the systems but no longer sells them.

The exploits affect ASA 5500-X Series devices that were made before Cisco added a pair of cybersecurity features called Secure Boot and Trust Anchor. According to the company, hackers can only exploit the flaws if customers activate the affected devices’ built-in virtual private networking feature.

CVE-2025-20362 makes it possible to bypass the VPN’s authentication feature and access network assets that are usually off limits. The other vulnerability, CVE-2025-20333, enables hackers to gain root access. It has a severity rating of 9.9 out of a maximum 10. Hackers are actively exploiting both vulnerabilities to launch cyberattacks. 

In a Thursday blog post, Cisco detailed that the cyberattacks were brought to its attention in May by a group of government agencies. The agencies had determined that the hackers used the ASA vulnerabilities to target federal networks. According to Cisco, the cyberattacks are believed to be part of a state-backed hacking campaign dubbed ArcaneDoor that it first discovered in 2024.

“The campaign is widespread and involves exploiting zero-day vulnerabilities to gain unauthenticated remote code execution on ASAs, as well as manipulating read-only memory (ROM) to persist through reboot and system upgrade,” CISA officials detailed in this week’s directive to federal agencies. 

Hackers used the disclosed zero-day flaws to install bootkit malware. When users power on an inflected device, the bootkit activates before the operating system launches. That allows the malware to remain on a system even if administrators reboot it or update the onboard firmware. Such configuration changes remove many other types of malware.

The cyberattacks compromised ASA firewalls’ ROMMON, a piece of firmware involved in booting the onboard operating system. Administrations also use the firmware for certain maintenance tasks such as recovering passwords. Cisco determined that the hackers used the vulnerabilities to download data, install malware and run terminal commands.

The hackers actively worked to evade detection. They disabled compromised devices’ logging mechanism, which made it more difficult to collected technical data about the breaches. In some cases, the hackers crashed infected systems to prevent diagnosis. 

Cisco patched the vulnerabilities on Thursday. It also released a fix for a third exploit that affects several of its software products. So far, Cisco has found no indication that the latter flaw is being used in cyberattacks.

CISA has instructed federal agencies to create an inventory of the vulnerable ASA systems in their networks. If a device has been breached or won’t be eligible for software updates after Sept. 30, it must be disconnected. Devices that don’t meet those criteria must be patched by 11:59 p.m. EDT today. 

Photo: Unsplash

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.

About News Media

News Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of News, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — News Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, News Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Volvo’s parent Geely to build $170 million joint factory in Vietnam · TechNode
Next Article Every Steam Deck Owner Should Install This App For Better Battery Life And Performance – BGR
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

If T-Mobile becomes an all-digital carrier, it will still be different than Verizon's Visible
News
How to Identify Burnout When You Work with Social Media |
Computing
Big Screens, Bigger Savings: Early Prime Big Deal Days Sales on TVs From Hisense, Toshiba, and More
News
Tencent invests €1.16 billion in new Ubisoft subsidiary, securing 25% stake and key IP rights · TechNode
Computing

You Might also Like

News

If T-Mobile becomes an all-digital carrier, it will still be different than Verizon's Visible

6 Min Read
News

Big Screens, Bigger Savings: Early Prime Big Deal Days Sales on TVs From Hisense, Toshiba, and More

6 Min Read
News

Get lifetime access to MS Office 2019 for under $30

2 Min Read
News

Big Google Home app redesign with ‘Ask Home’ starts rolling out on iPhone

4 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?