Unbelievable!
Cisco has a long history of producing network gear where security is an important feature, so why haven't their code writing and QA processes evolved to avoid and/or detect security bugs before the product is released?
Cybersecurity agencies on both sides of the Atlantic are sounding the alarm over Cisco firewall vulnerabilities that are being exploited by an "advanced threat actor." The Cybersecurity and Infrastructure Security Agency (CISA) issued an Emergency Directive on Thursday, saying there is "an unacceptable risk" to government …
The advisory is for organisations to:
- patch equipment
- remove any end of life equipment ASAP as at best, it has another month of vendor support.
Insert whatever vendor you wish into those statements and it remains true.
While it would be nice if Cisco or any other vendor could write perfect code that anticipated any possibility, we have to accept reality isn't that perfect.
CEO: Hello CFO, how about our bonus for this year?
CFO: There have been some extra expenses in the software division. It may be necessary to limit our expenses.
CTO: Oh, no problem. There are some very expensive senior staff that should be replaced with that new thingy, whatayoucallit, vibe something. It is much cheaper and allows us to reallocate funds to where it matters.
CEO: How many shall we get rid of? 10%?, 20%?
CFO: I'd say 30% need to go for our bonus targets to be met.
CTO: No problem!
CEO: Hello HR, please fire 30% of our most expensive slaves in the software division.
HR: Sure about that?
CEO, CFO, CTO: Yes.
HR: OK.
CEO, CFO, CTO: <smile>Payday</smile>
CVE-2025-20333 is a critical buffer overflow vulnerability .. is caused by improper validation of user-supplied input in HTTP(S) requests to the web service, exposing vulnerable Cisco firewall systems to the threat of arbitrary code execution with root privileges.
>> Censys uncovered links to major Chinese networks
Does Censys ever uncover links to major US networks? Or is it blind in that direction? If it is blind then it can't be trusted.
If the UK was serious about network security it would banish Cisco once and for all. The number of backdoors, mysteriously forgotten hard-coded passwords, unusual packet overflows that keep being found in Cisco equipment somehow gets a free pass. Over and over and over and over.
Or is it a case of "we knew about it all along and have been exploiting it, but now it's known publicly we don't want anyone else to use it"?
...wasn't Chinese spying and horrible security the reason everybody was pressured into getting rid of their Heaiwai, Haeawa... oh however the hell you spell it, it was deemed bad bad bad...
...and yet, this stuff is just the same only different. Maybe we ought to blacklist Cisco too?
"The networking giant has also admitted that it knew these flaws were being exploited as far back as May, when government incident responders called it in to help investigate intrusions on ASA 5500-X firewalls. Attackers were already dropping implants, running commands, and siphoning data"
Which government out of curiosity, the article doesn't make that clear. The cynic in me says whichever government it was, wanted to use it themselves for while before raising any flags.
Regardless, 4 months between spotting an exploit actively in use in the wild and patching is damming for Cisco. Given their gear is used by a lot of agencies, you would hope a swift foot up the rear-end is winging it's way to Cisco.
But if you don't want to use Cisco, who else is there? Palo Alta? Fortinet? Juniper?
Personally in order of speed for patching I'd rank them in order of Juniper, Palo Alta, Fortinet then Cisco, but that just my own personal back of an envelope opinion.
I think you may have misunderstood the timeline:
- Cisco pinned the activity on a threat crew it dubbed UAT4356, which had been abusing the bugs to compromise government systems worldwide since November 2023.
- ArcaneDoor first came to light in April 2024, when Cisco patched two zero-day flaws in ASA and FTD firewalls that had already been exploited to break into government and telecom networks.
- multiple reminders including major pushs in May 2025 and September 2025 to patch corresponding to end of sale/end of support dates for the firewalls most likely to be impacted (i.e. unpatched or rarely patched since purchase)
There's a combination of factors:
- the 5500 series have no secure boot so are vulnerable to exploits where the threat is persistent.
- depending on the release train, some of the patches have been out for weeks or months (i.e. 9.16.4.84 fixes some of the issues listed and was released in April, 9.20.4.10 was released on September 3rd and fully addresses the issues). Being patched to July/August interim releases on older platforms at least reduced you to a single vulnerability versus multiple vulnerabilities that appear to be used in known attack chains.