Vulnerability Watch

Forum Discussion

snarang's avatar
snarang
Product Team
2 months ago

FAQ on Exploited Zero-Day Flaws in Cisco ASA and FTD Devices (CVE-2025-20333, CVE-2025-20362)

On September 25, Cisco published three advisories for three zero-day vulnerabilities in its Cisco Adaptive Security Appliance (ASA) Software and Firewall Threat Defense (FTD) Software:

CVEDescriptionCVSSv3Exploited
CVE-2025-20333Cisco ASA and FTD Software VPN Web Server Remote Code Execution Vulnerability (RCE)9.9Yes
CVE-2025-20362Cisco ASA and FTD Software VPN Web Server Unauthorized Access Vulnerability6.5Yes
CVE-2025-20363Cisco ASA and FTD Software, IOS Software, IOS XE Software, and IOS XR Software Web Services9.0No

According to Cisco, two of the three zero-day vulnerabilities were exploited in the wild by the same threat actor behind 2024's ArcaneDoor campaign that also involved the exploitation of flaws in Cisco devices.

For more information about the vulnerability, including the availability of patches and Tenable product coverage, please visit our blog.

No RepliesBe the first to reply