The Register Home Page

back to article UK and US security agencies order urgent fixes as Cisco firewall bugs exploited in wild

Cybersecurity agencies on both sides of the Atlantic are sounding the alarm over Cisco firewall vulnerabilities that are being exploited by an "advanced threat actor." The Cybersecurity and Infrastructure Security Agency (CISA) issued an Emergency Directive on Thursday, saying there is "an unacceptable risk" to government …

  1. Andy E
    FAIL

    Unbelievable!

    Cisco has a long history of producing network gear where security is an important feature, so why haven't their code writing and QA processes evolved to avoid and/or detect security bugs before the product is released?

    1. theblackhand

      Re: Unbelievable!

      The advisory is for organisations to:

      - patch equipment

      - remove any end of life equipment ASAP as at best, it has another month of vendor support.

      Insert whatever vendor you wish into those statements and it remains true.

      While it would be nice if Cisco or any other vendor could write perfect code that anticipated any possibility, we have to accept reality isn't that perfect.

  2. b0llchit Silver badge
    Trollface

    Meanwhile @Cisco

    CEO: Hello CFO, how about our bonus for this year?

    CFO: There have been some extra expenses in the software division. It may be necessary to limit our expenses.

    CTO: Oh, no problem. There are some very expensive senior staff that should be replaced with that new thingy, whatayoucallit, vibe something. It is much cheaper and allows us to reallocate funds to where it matters.

    CEO: How many shall we get rid of? 10%?, 20%?

    CFO: I'd say 30% need to go for our bonus targets to be met.

    CTO: No problem!

    CEO: Hello HR, please fire 30% of our most expensive slaves in the software division.

    HR: Sure about that?

    CEO, CFO, CTO: Yes.

    HR: OK.

    CEO, CFO, CTO: <smile>Payday</smile>

    1. vogon00

      Re: Meanwhile @Cisco

      CEO, CFO, CTO: Payday

      Probably true. However don't forget the CEO/Board are responsible for delivering value to the shareholders and needing to meet the analyst's forecasts. That's another form of pressure the C-suite are under.

      1. Anonymous Coward
        Anonymous Coward

        Re: Meanwhile @Cisco

        They're not the victims anyone should have sympathy for.

  3. Anonymous Coward
    Anonymous Coward

    It's déjà vu all over again, Yogi

    CVE-2025-20333 is a critical buffer overflow vulnerability .. is caused by improper validation of user-supplied input in HTTP(S) requests to the web service, exposing vulnerable Cisco firewall systems to the threat of arbitrary code execution with root privileges.

  4. VoiceOfTruth Silver badge

    Censys

    >> Censys uncovered links to major Chinese networks

    Does Censys ever uncover links to major US networks? Or is it blind in that direction? If it is blind then it can't be trusted.

    If the UK was serious about network security it would banish Cisco once and for all. The number of backdoors, mysteriously forgotten hard-coded passwords, unusual packet overflows that keep being found in Cisco equipment somehow gets a free pass. Over and over and over and over.

    Or is it a case of "we knew about it all along and have been exploiting it, but now it's known publicly we don't want anyone else to use it"?

  5. heyrick Silver badge

    Hmmm...

    ...wasn't Chinese spying and horrible security the reason everybody was pressured into getting rid of their Heaiwai, Haeawa... oh however the hell you spell it, it was deemed bad bad bad...

    ...and yet, this stuff is just the same only different. Maybe we ought to blacklist Cisco too?

    1. IGotOut Silver badge

      Re: Hmmm...

      The difference was was Huawei was very capable kit at a "low" made by the Chinese that had piss poor security, whereas Cisco is fairy capable kit, at a high price, made in the USA that has piss poor security.

  6. Decay

    "The networking giant has also admitted that it knew these flaws were being exploited as far back as May, when government incident responders called it in to help investigate intrusions on ASA 5500-X firewalls. Attackers were already dropping implants, running commands, and siphoning data"

    Which government out of curiosity, the article doesn't make that clear. The cynic in me says whichever government it was, wanted to use it themselves for while before raising any flags.

    Regardless, 4 months between spotting an exploit actively in use in the wild and patching is damming for Cisco. Given their gear is used by a lot of agencies, you would hope a swift foot up the rear-end is winging it's way to Cisco.

    But if you don't want to use Cisco, who else is there? Palo Alta? Fortinet? Juniper?

    Personally in order of speed for patching I'd rank them in order of Juniper, Palo Alta, Fortinet then Cisco, but that just my own personal back of an envelope opinion.

    1. VoiceOfTruth Silver badge

      >> who else is there

      Huawei. They have had their source code reviewed. Unlike Cisco.

    2. Anonymous Coward
      Anonymous Coward

      I think you may have misunderstood the timeline:

      - Cisco pinned the activity on a threat crew it dubbed UAT4356, which had been abusing the bugs to compromise government systems worldwide since November 2023.

      - ArcaneDoor first came to light in April 2024, when Cisco patched two zero-day flaws in ASA and FTD firewalls that had already been exploited to break into government and telecom networks.

      - multiple reminders including major pushs in May 2025 and September 2025 to patch corresponding to end of sale/end of support dates for the firewalls most likely to be impacted (i.e. unpatched or rarely patched since purchase)

      1. Decay

        My quote was directly from the article. (2nd paragraph, 1st line)

        Are you saying that Cisco had previously issued patches to address the exploit patched on Thursday evening? Or are you saying this was known since way earlier without a patch until Thursday?

        1. Anonymous Coward
          Anonymous Coward

          There's a combination of factors:

          - the 5500 series have no secure boot so are vulnerable to exploits where the threat is persistent.

          - depending on the release train, some of the patches have been out for weeks or months (i.e. 9.16.4.84 fixes some of the issues listed and was released in April, 9.20.4.10 was released on September 3rd and fully addresses the issues). Being patched to July/August interim releases on older platforms at least reduced you to a single vulnerability versus multiple vulnerabilities that appear to be used in known attack chains.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like