Vulnerability Management, Patch/Configuration Management

Cisco urged to clarify cybersecurity flaws’ business impact

Senate Committee on Health, Education, Labor, and Pensions Chair Bill Cassidy, R-La., has called on Cisco Systems to provide more transparency about the impact of recent cybersecurity vulnerabilities, tracked as CVE-2025-20362 and CVE-2025-30333, that led to an emergency federal directive last month, reports The Record, a news site by cybersecurity firm Recorded Future.

"Any vulnerability in Cisco's systems would jeopardize this access for millions of Americans," wrote Cassidy in a letter to Cisco CEO Chuck Robbins, which also urged the company to work with both private stakeholders and the government to ensure protection.

The Cybersecurity and Infrastructure Security Agency issued an emergency directive on Sept. 25 requiring agencies to fix the flaws affecting Cisco Adaptive Security Appliances. Cisco later confirmed that it worked with multiple U.S. government agencies to investigate the intrusions targeting multiple 5500-X Series devices, some of which had reached end of support. International partners, including Australia, the UK, and Canada, issued similar alerts.

Cisco's analysis linked the attacks to the same group behind last year's ArcaneDoor campaign. CISA Acting Director Madhu Gottumukkala said the vulnerabilities could be exploited "with alarming ease" and urged all organizations using Cisco devices to apply immediate fixes.

Related Events

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds