The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an emergency directive urging federal agencies to address critical vulnerabilities in Cisco firewall devices. These flaws, identified as CVE-2025-20333 and CVE-2025-20362, have been actively exploited by a suspected state-sponsored group, ArcaneDoor. The vulnerabilities allow attackers to execute arbitrary code and escalate privileges, posing significant risks to federal networks and critical infrastructure. Agencies have been instructed to inventory affected devices, apply necessary updates, and disconnect compromised hardware by October 2, 2025.
Urgent Cybersecurity Directive Issued
On September 25, 2025, CISA issued Emergency Directive 25-03, mandating all federal civilian agencies to take immediate action to address vulnerabilities in Cisco Adaptive Security Appliances (ASA) and Firepower firewall devices. The identified flaws—CVE-2025-20333 and CVE-2025-20362—are being actively exploited in a widespread attack campaign. CVE-2025-20333, in particular, is rated 9.9/10 in severity, allowing attackers to modify read-only memory (ROM) and maintain persistence even after reboots and upgrades. CISA has directed agencies to inventory their Cisco devices, conduct forensic analysis, disconnect compromised hardware, and apply necessary updates by October 2, 2025. The vulnerabilities have been added to CISA’s Known Exploited Vulnerabilities catalog, mandating all agencies to patch or discontinue use of the affected systems by October 16, 2025.
Attribution and Threat Actor Profile
The ongoing cyberattacks are attributed to ArcaneDoor, a suspected state-sponsored group also known as Storm-1849 by Microsoft. This group has been linked to similar activity since early 2024. The attackers are employing advanced evasion techniques, including disabling logging and crashing devices, to exploit the vulnerabilities. New malware strains, dubbed RayInitiator and Line Viper, have emerged, demonstrating greater sophistication and evasion capabilities. While CISA has not formally attributed the attacks to a specific nation-state, cybersecurity researchers and firms like Palo Alto Networks strongly link the campaign to actors based in China.
Global Response and Cisco's Recommendations
In addition to CISA's directive, the UK's National Cyber Security Centre (NCSC) has issued urgent warnings to Cisco ASA 5500-X Series customers following the discovery of the critical vulnerabilities. Both CISA and NCSC have advised immediate updates or replacements of vulnerable hardware. Cisco has urged customers to upgrade their devices to new software versions that fix the flaws and eliminate the intruders' footholds. The company has been working with various government agencies since May to address these intrusions, which involve hackers exploiting firewall vulnerabilities to implant malware, execute commands, and potentially extract data.
Broader Implications and Ongoing Threats
The vulnerabilities in Cisco devices are widely used across government, enterprise, education, and security sectors, increasing the stakes of the ongoing threats. The exploitation of these flaws underscores the critical need for robust cybersecurity measures and timely patching of known vulnerabilities. Organizations are urged to follow the guidance provided by CISA and Cisco to mitigate the risks and protect their networks from potential breaches.
Comments