Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Cisco Warns of New Firewall Attack Exploiting CVE-2025-20333 and CVE-2025-20362

Cisco Warns of New Firewall Attack Exploiting CVE-2025-20333 and CVE-2025-20362

Posted on November 6, 2025November 6, 2025 By CWS

Nov 06, 2025Ravie LakshmananZero-Day / Vulnerability
Cisco on Wednesday disclosed that it grew to become conscious of a brand new assault variant that is designed to focus on units working Cisco Safe Firewall Adaptive Safety Equipment (ASA) Software program and Cisco Safe Firewall Menace Protection (FTD) Software program releases which are vulnerable to CVE-2025-20333 and CVE-2025-20362.
“This assault could cause unpatched units to unexpectedly reload, resulting in denial-of-service (DoS) circumstances,” the corporate stated in an up to date advisory, urging clients to use the updates as quickly as potential.
Each vulnerabilities have been disclosed in late September 2025, however not earlier than they have been exploited as zero-day vulnerabilities in assaults delivering malware akin to RayInitiator and LINE VIPER, in accordance with the U.Ok. Nationwide Cyber Safety Centre (NCSC).

Whereas profitable exploitation of CVE-2025-20333 permits an attacker to execute arbitrary code as root utilizing crafted HTTP requests, CVE-2025-20362 makes it potential to entry a restricted URL with out authentication.
The replace comes as Cisco addressed two essential safety flaws in Unified Contact Middle Specific (Unified CCX) that would allow an unauthenticated, distant attacker to add arbitrary recordsdata, bypass authentication, execute arbitrary instructions, and elevate privileges to root.
The networking tools main credited safety researcher Jahmel Harris for locating and reporting the shortcomings. The vulnerabilities are listed beneath –

CVE-2025-20354 (CVSS rating: 9.8) – A vulnerability within the Java Distant Technique Invocation (RMI) strategy of Unified CCX that enables an attacker to add arbitrary recordsdata and execute arbitrary instructions with root permissions on an affected system.
CVE-2025-20358 (CVSS rating: 9.4) – A vulnerability within the Contact Middle Specific (CCX) Editor software of Unified CCX that enables an attacker to bypass authentication and procure administrative permissions to create arbitrary scripts on the underlying working system and execute them.

They’ve been addressed within the following variations –

Cisco Unified CCX Launch 12.5 SU3 and earlier (Fastened in 12.5 SU3 ES07)
Cisco Unified CCX Launch 15.0 (Fastened in 15.0 ES01)

Along with the 2 vulnerabilities, Cisco has shipped patches for a high-severity DoS bug (CVE-2025-20343, CVSS rating: 8.6) in Identification Providers Engine (ISE) that would enable an unauthenticated, distant attacker to trigger a vulnerable machine to restart unexpectedly.
“This vulnerability is because of a logic error when processing a RADIUS entry request for a MAC tackle that’s already a rejected endpoint,” it stated. “An attacker may exploit this vulnerability by sending a particular sequence of a number of crafted RADIUS entry request messages to Cisco ISE.”
Whereas there isn’t a proof that any of the three safety flaws have been exploited within the wild, it is important that customers apply the updates as quickly as potential for optimum safety.

The Hacker News Tags:Attack, Cisco, CVE202520333, CVE202520362, Exploiting, Firewall, Warns

Post navigation

Previous Post: Gootloader is Back with New ZIP File Trickery that Decive the Malicious Payload
Next Post: Trojanized ESET Installers Drop Kalambur Backdoor in Phishing Attacks on Ukraine

Related Posts

WhatsApp Issues Emergency Update for Zero-Click Exploit Targeting iOS and macOS Devices WhatsApp Issues Emergency Update for Zero-Click Exploit Targeting iOS and macOS Devices The Hacker News
Android Droppers Now Deliver SMS Stealers and Spyware, Not Just Banking Trojans Android Droppers Now Deliver SMS Stealers and Spyware, Not Just Banking Trojans The Hacker News
Zero-Day Exploits, Insider Threats, APT Targeting, Botnets and More Zero-Day Exploits, Insider Threats, APT Targeting, Botnets and More The Hacker News
Why Organizations Are Abandoning Static Secrets for Managed Identities Why Organizations Are Abandoning Static Secrets for Managed Identities The Hacker News
Critical Langflow Flaw Added to CISA KEV List Amid Ongoing Exploitation Evidence Critical Langflow Flaw Added to CISA KEV List Amid Ongoing Exploitation Evidence The Hacker News
New U.S. Visa Rule Requires Applicants to Set Social Media Account Privacy to Public New U.S. Visa Rule Requires Applicants to Set Social Media Account Privacy to Public The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Russian Group Star Blizzard Utilizes DarkSword iOS Exploit
  • Secrets Sprawl Expands in 2026: Key Insights for CISOs
  • Urgent Patches Address Critical Grafana Security Flaws
  • Telnyx Python SDK Faces Supply Chain Attack
  • Russian Toolkit Exploits RDP via Malicious LNK Files

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Russian Group Star Blizzard Utilizes DarkSword iOS Exploit
  • Secrets Sprawl Expands in 2026: Key Insights for CISOs
  • Urgent Patches Address Critical Grafana Security Flaws
  • Telnyx Python SDK Faces Supply Chain Attack
  • Russian Toolkit Exploits RDP via Malicious LNK Files

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark