Vulnerable Cisco Adaptive Security Appliance and Firewall Threat Defense devices impacted by the CVE-2025-20333 and CVE-2025-20362 flaws have been targeted with a new wave of intrusions since May, reports The Register.Attacks aimed at impacted firewalls prompted persistent reloads that subsequently led to denial-of-service conditions, according to an updated alert from Cisco, which linked the illicit activity and previous intrusions to the ArcaneDoor threat operation. Such a development comes as the firm issued fixes for a pair of critical issues affecting its Unified Contact Center Express software.More severe of the two is the improper authentication mechanism-linked Java Remote Method Invocation process bug, tracked as CVE-2025-20354, which could be leveraged to facilitate arbitrary code execution on the operating system and privilege escalation to root.On the other hand, exploitation of the authentication bypass defect CVE-2025-20358, which stems from improper CCX Editor and Unified CCX server authentication, could prompt arbitrary script execution. No active exploitation of either flaw has been observed so far.
Vulnerability Management, Network Security
Another Cisco ASA firewall attack wave uncovered
(Adobe Stock)
An In-Depth Guide to Network Security
Get essential knowledge and practical strategies to fortify your network security.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
