Cisco ASA customers urged to take immediate action as NCSC, CISA issue critical vulnerability warnings
Cisco customers are urged to upgrade and secure systems immediately
Security agencies are warning that hackers are exploiting vulnerabilities in Cisco Adaptive Security Appliance (ASA) 5500-X Series devices to install malware, execute commands, and steal data.
The first vulnerability, tracked as CVE-2025-20333, allows authenticated attackers to execute arbitrary code on devices using ASA and Firewall Threat Defense (FTD) software.
Meanwhile, a second vulnerability (CVE-2025-20362) allows them to access restricted URL endpoints without authentication.
30% off Keeper Security's Business Starter and Business plans
Keeper Security is trusted and valued by thousands of businesses and millions of employees. Why not join them and protect your most important assets while taking advantage of this special offer?
"In May 2025, Cisco was engaged by multiple government agencies that provide incident response services to government organizations to support the investigation of attacks that were targeting certain Cisco Adaptive Security Appliance (ASA) 5500-X Series devices that were running Cisco Secure Firewall ASA Software with VPN web services enabled," the networking giant said in a customer advisory.
"Attackers were observed to have exploited multiple zero-day vulnerabilities and employed advanced evasion techniques such as disabling logging, intercepting CLI commands, and intentionally crashing devices to prevent diagnostic analysis."
CISA, NCSC respond to Cisco ASA flaws
According to the US Cybersecurity and Infrastructure Security Agency (CISA), the campaign is 'widespread' and connected with “ArcaneDoor” activity identified early last year
This threat campaign targeted perimeter network devices from several vendors, including Cisco, to deliver malware strains such as Line Runner and Line Dancer.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
"CISA is directing agencies to account for all Cisco ASA and Firepower devices, collect forensics and assess compromise via CISA-provided procedures and tools, disconnect end-of-support devices, and upgrade devices that will remain in service," the agency said.
The UK's National Cyber Security Centre (NCSC) has also issued guidance in the wake of the exploitation. The cybersecurity agency noted that some Cisco ASA 5500-X series models will be out of support from September 2025 and August 2026.
With this in mind, enterprises using these models should take immediate action to mitigate potential risks.
“It is critical for organizations to take note of the recommended actions highlighted by Cisco today, particularly on detection and remediation,” said NCSC chief technology officer Ollie Whitehouse.
“We strongly encourage network defenders to follow vendor best practices and engage with the NCSC’s malware analysis report to assist with their investigations.
“End-of-life technology presents a significant risk for organisations. Systems and devices should be promptly migrated to modern versions to address vulnerabilities and strengthen resilience.”
New malware strains are a potent threat
New RayInitiator and Line Viper malware strains believed to be used in attacks represent a “significant evolution” on Line Dancer and Line Runner, the NCSC warned, particularly in terms of sophistication and their ability to evade detection.
CISA has now issued a directive ordering federal agencies - which have already been targeted - to identify, analyze, and mitigate potential compromises immediately.
"CISA is directing agencies to account for all Cisco ASA and Firepower devices, collect forensics and assess compromise via CISA-provided procedures and tools, disconnect end-of-support devices, and upgrade devices that will remain in service," it said.
"These actions are directed to address the immediate risk, assess compromise, and inform analysis of the ongoing threat actor campaign.”
Make sure to follow ITPro on Google News to keep tabs on all our latest news, analysis, and reviews.
MORE FROM ITPRO
- Cisco polishes its platform but the network is still king
- 96% of businesses have low cyber-readiness, claims Cisco
- Cisco promises AI training for a million Americans
Emma Woollacott is a freelance journalist writing for publications including the BBC, Private Eye, Forbes, Raconteur and specialist technology titles.
-
Broadcom eyes security, performance boosts with vDefend and Avi Load Balancer updatesNews Enhancements to VMware vDefend and VMware Avi Load Balancer use AI-powered automation to help secure private cloud environments
-
How business leaders are using the Dell Pro 7 and Dell Pro 5Sponsored Thanks to flexibility and a range of spec options, the Dell Pro 7 and Pro 5 laptops can suit a variety of business leaders across a mix of workplaces
-
NCSC issues alert over 'zero-click' phishing campaign hitting enterprisesNews Ukrainian organizations were used to test new zero-click techniques employed by Russian hackers
-
'Perimeter defences are prime targets': Security experts issue alert over Palo Alto GlobalProtect VPN exploitationNews The flaw in Palo Alto Networks’ GlobalProtect VPN was recently upgraded from a ‘medium’ rating to ‘high’
-
Cisco just launched two cyber-focused small language models: Antares-350M and Antares-1B aim to supercharge codebase analysis – and they run at a “fraction of the compute expense” of popular frontier modelsNews The Antares models unveiled by Cisco aim to cut costs in codebase analysis
-
‘The risk to every organization has increased exponentially’: The FortiBleed campaign just took a turn for the worseNews Reports suggest that FortiBleed-linked exposed credentials could put UK government and public services at huge risk
-
Hackers are posing as Interpol to target small businesses – here's what you need to knowNews Small businesses are warned to think twice before clicking on links
-
Opera browser thinks it has the solution to stopping ClickFix malware attacksNews The browser company is targeting a growing source of malicious links with its new Paste Protect feature
-
‘Hacking groups have the transport network firmly in their sights’: Network Rail is battling a torrent of cyber threatsNews FoI requests have revealed that the rail operator is under increasing attack, as cyber criminals set their sights on the transport sector
-
‘This operation marked a shift in strategy’: Three notorious malware networks have been taken down using RICO legislationNews The action involved the use of US racketeering laws to treat two malware families as part of a single conspiracy
