Full Report
AL25-012 - Vulnerabilities impacting Cisco ASA and FTD devices – CVE-2025-20333, CVE-2025-20362 and CVE-2025-20363 – Update 1
Analysis Summary
# Vulnerability: Multiple Flaws in Cisco ASA and FTD Devices
## CVE Details
- **CVE ID:** CVE-2025-20333, CVE-2025-20362, CVE-2025-20363
- **CVSS Score:** Critical (Numerical scores not explicitly listed in text, but categorized as "Critical")
- **CWE:** Improper validation of user-supplied input (specific CWE IDs not provided in the summary)
## Affected Systems
- **Products:**
- Cisco Adaptive Security Appliance (ASA) 5500-X Series
- Cisco Secure Firewall Threat Defense (FTD)
- Cisco Firepower eXtensible Operating System (FXOS)
- Cisco IOS, IOS XE, and IOS XR (Specifically for CVE-2025-20363)
- **Versions:**
- **Cisco ASA:** 9.12 (<9.12.4.72), 9.14 (<9.14.4.28), 9.16 (<9.16.4.85), 9.17 (<9.17.1.45), 9.18 (<9.18.4.67), 9.19 (<9.19.1.42), 9.20 (<9.20.4.10), 9.22 (<9.22.2.14), 9.23 (<9.23.1.19)
- **Cisco FTD:** 7.0 (<7.0.8.1), 7.1 (All), 7.2 (<7.2.10.2), 7.3 (All), 7.4 (<7.4.2.4), 7.6 (<7.6.2.1), 7.7 (<7.7.10.1)
- **Configurations:** Devices with VPN web services enabled.
## Vulnerability Description
The vulnerabilities stem from the improper validation of user-supplied input in HTTP(S) requests.
- **CVE-2025-20333:** Allows authenticated remote attackers to execute arbitrary code.
- **CVE-2025-20362:** Allows unauthenticated remote attackers to bypass authentication and access restricted URL endpoints.
- **CVE-2025-20363:** Allows unauthenticated (ASA/FTD) or low-privileged authenticated (IOS/XE/XR) remote attackers to execute arbitrary code.
**Persistence Note:** A "FIRESTARTER" backdoor persistence method has been identified within the FXOS base operating system. This mechanism can survive device upgrades to patched versions.
## Exploitation
- **Status:** **Exploited in the wild.** Active exploitation targeting ASA 5500-X series has been observed.
- **Complexity:** Not explicitly defined, but likely Low to Medium given the remote unauthenticated vector for certain CVEs.
- **Attack Vector:** Network (Remote)
## Impact
- **Confidentiality:** High (Arbitrary code execution and unauthorized endpoint access)
- **Integrity:** High (Ability to achieve persistent backdoor access)
- **Availability:** High (Potential for full system takeover)
## Remediation
### Patches
Apply the specific "Fixed Release" versions identified for each product line:
- **ASA:** Upgrade to the latest sub-versions (e.g., 9.23.1.19, 9.22.2.14, etc.).
- **FTD:** Upgrade to fixed releases (e.g., 7.7.10.1, 7.6.2.1, 7.4.2.4, etc.).
### Workarounds
The article does not provide specific configuration workarounds; immediate patching and forensic checking for persistence are recommended.
## Detection
- **Indicators of Compromise:** Look for unauthorized persistence in the FXOS layer (backdoor known as "FIRESTARTER").
- **Methods:**
- Consult the Cisco Talos blog post regarding UAT-4356/FIRESTARTER.
- Refer to CISA Malware Analysis Report AR26-113A.
- Review CISA Emergency Directive ED 25-03 for mitigation and identification steps.
## References
- Cisco Security Advisory (Persistence): hxxps[://]sec[.]cloudapps[.]cisco[.]com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-persist-CISAED25-03
- Cisco Talos Blog: hxxps[://]blog[.]talosintelligence[.]com/uat-4356-firestarter/
- CISA ED 25-03: hxxps[://]www[.]cisa[.]gov/news-events/directives/v1-ed-25-03-identify-and-mitigate-potential-compromise-cisco-devices
- Canadian Centre for Cyber Security Alert: hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/al25-012-vulnerabilities-impacting-cisco-asa-ftd-devices-cve-2025-20333-cve-2025-20362-cve-2025-20363