Vulnerabilità ed exploit · Spionaggio APT

Cisco Firewall Backdoors Survive Patching

Cisco ASA and FTD devices can stay compromised after the patch lands. The standard response — fix the CVEs and move on — misses that FIRESTARTER can remain active and let attackers come back without re-exploiting the original flaw.

CISA and the UK NCSC say FIRESTARTER is tied to a widespread campaign that used CVE-2025-20333 and CVE-2025-20362 to get initial access to Cisco ASA firmware. They assess the backdoor can persist on ASA and Firepower Threat Defense systems, and CISA has updated Emergency Directive 25-03 after finding suspicious connections on a U.S. federal agency device.

The risk is no longer just vulnerable firmware. Infected appliances can keep serving as a foothold after updates, so patching removes exposure to the exploit but does not prove the device is clean.

15 fonti · 27 apr

CVE-2025-20362

NVD KEV

Sfruttamento noto · CISA KEV

CVSS 6.5 MEDIUM: update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA… EPSS 87% (100º percentile).

Data di correzione federale CISA 26 set · data superata

CVE-2025-20333

NVD KEV

Sfruttamento noto · CISA KEV

CVSS 9.9 CRITICAL: a vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco… EPSS 71% (99º percentile).

Data di correzione federale CISA 26 set · data superata

Cronologia

Fonti

Riepilogo fornitore: Cisco

Part of the PlainSec briefing for 2026-04-28

Every edition of this story: Cisco Firewall Backdoors Survive Patching

Altro da oggi