Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Avatar vs. Twin: The Future of Digital Selves

Peloton recalls 833,000 bikes after reports of injuries

Trojanized ESET installer drops Kalambur backdoor in phishing attack on Ukraine

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Cisco warns of new firewall attacks exploiting CVE-2025-20333 and CVE-2025-20362
Identity

Cisco warns of new firewall attacks exploiting CVE-2025-20333 and CVE-2025-20362

userBy userNovember 6, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

November 6, 2025Ravi LakshmananZero-day/vulnerabilities

Cisco warns of new firewall attacks

Cisco announced Wednesday that it has become aware of a new attack variant that targets devices running Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software releases susceptible to CVE-2025-20333 and CVE-2025-20362.

“This attack could cause unpatched devices to reload unexpectedly, leading to a denial of service (DoS) condition,” the company said in its latest advisory, urging customers to apply the update as soon as possible.

According to the UK’s National Cyber ​​Security Center (NCSC), both vulnerabilities were disclosed in late September 2025, but prior to that they were exploited as zero-day vulnerabilities in attacks that distributed malware such as RayInitiator and LINE VIPER.

DFIR retainer service

Successful exploitation of CVE-2025-20333 allows the attacker to execute arbitrary code as root via a crafted HTTP request, while CVE-2025-20362 allows the attacker to access restricted URLs without authentication.

This update comes after Cisco addressed two critical security flaws in Unified Contact Center Express (Unified CCX) that could allow an unauthenticated, remote attacker to upload arbitrary files, bypass authentication, execute arbitrary commands, and escalate privileges to root.

The networking equipment giant acknowledged that security researcher Jamel Harris discovered and reported the flaw. The vulnerabilities are listed below –

CVE-2025-20354 (CVSS Score: 9.8) – A vulnerability in the Java Remote Method Invocation (RMI) process in Unified CCX allows an attacker to upload arbitrary files and execute arbitrary commands with root privileges on an affected system. CVE-2025-20358 (CVSS Score: 9.4) – A vulnerability in the Contact Center Express (CCX) Editor application in Unified CCX allows an attacker to bypass authentication, gain administrative privileges, and create and execute arbitrary scripts on the underlying operating system.

These are addressed in the next version.

Cisco Unified CCX Release 12.5 SU3 and earlier (fixed in 12.5 SU3 ES07) Cisco Unified CCX Release 15.0 (fixed in 15.0 ES01)

CIS build kit

In addition to the two vulnerabilities, Cisco has shipped a patch for a high-severity DoS bug (CVE-2025-20343, CVSS score: 8.6) in Identity Services Engine (ISE). This bug could allow an unauthenticated, remote attacker to cause a vulnerable device to restart unexpectedly.

“The vulnerability is due to a logic error in processing RADIUS access requests for MAC addresses that are already denied endpoints.” “An attacker could exploit this vulnerability by sending a specific sequence of multiple crafted RADIUS Access Request messages to Cisco ISE.”

Although there is no evidence that the three security flaws have been exploited in the wild, it is important for users to apply the updates as soon as possible for optimal protection.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleWhy Benchmark made a rare crypto bet on trading app Fomo with $17 million Series A
Next Article Trojanized ESET installer drops Kalambur backdoor in phishing attack on Ukraine
user
  • Website

Related Posts

Trojanized ESET installer drops Kalambur backdoor in phishing attack on Ukraine

November 6, 2025

Building cyber resilience in financial services

November 6, 2025

AI Tools in Malware, Botnets, GDI Flaws, Election Attacks & More

November 6, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Avatar vs. Twin: The Future of Digital Selves

Peloton recalls 833,000 bikes after reports of injuries

Trojanized ESET installer drops Kalambur backdoor in phishing attack on Ukraine

Cisco warns of new firewall attacks exploiting CVE-2025-20333 and CVE-2025-20362

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Meet Your Digital Twin: Europe’s Cutting-Edge AI is Personalizing Medicine

TwinH: The AI Game-Changer for Faster, More Accessible Legal Services

Immortality is No Longer Science Fiction: TwinH’s AI Breakthrough Could Change Everything

The AI Revolution: Beyond Superintelligence – TwinH Leads the Charge in Personalized, Secure Digital Identities

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.