CISA Directs Federal Agencies to Identify and Mitigate Potential Compromise of Cisco Devices


Today, CISA issued Emergency Directive ED 25-03: Identify and Mitigate Potential Compromise of Cisco Devices to address vulnerabilities in Cisco Adaptive Security Appliances (ASA) and Cisco Firepower devices. CISA has added vulnerabilities CVE-2025-20333 and CVE-2025-20362 to the Known Exploited Vulnerabilities Catalog.

The Emergency Directive requires federal agencies to identify, analyze, and mitigate potential compromises immediately. Agencies must: Identify all instances of Cisco ASA and Cisco Firepower devices in operation (all versions). Collect and transmit memory files to CISA for forensic analysis by 11:59 p.m. EST Sept. 26.

Read more…
Source: US Cybersecurity and Infrastructure Security Agency


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • Korea, US to Begin Joint Investment in and Research on Cyber Security in Late May

    May 22, 2017

    Threats of More intelligent worldwide cyber attacks of these days are strengthening cyber security alliance between Korea and the United States.  According to the Korean Ministry of Science, ICT and Future Planning, the Korean government and the US government (Air Force Research Laboratory) will finalize the selection of a research consortium for the start of joint ...

  • FDA, Industry Look for Gaps in Cybersecurity

    May 18, 2017

    The US Food and Drug Administration (FDA) on Thursday kicked off a fortuitously-timed public workshop on medical device cybersecurity, the agency’s third on the subject to date. At the workshop, FDA officials, representatives from industry and researchers are trying to determine the current gaps in regulatory science as it relates to cybersecurity with the aim of ...

  • Ransomware attack inflames intelligence scrutiny

    May 16, 2017

    The “Wanna Cry” ransomware attack producing global shockwaves has renewed focus on the activities of the National Security Agency (NSA) and how the government decides to disclose cyber vulnerabilities to the private sector. The ransomware campaign, which broke out on Friday and has spread to at least 150 countries and 300,000 machines, is widely believed to ...

  • Donald Trump signs executive order on cybersecurity

    May 13, 2017

    President Donald Trump has signed an executive order to increase the White House’s role in the nation’s cybersecurity. The order assigns responsibility for protecting federal networks and critical infrastructure to the executive branch of government. The executive order declares that the heads of executive departments and agencies are to be held accountable for managing the cybersecurity risk ...

  • NSA Admits They’re Reviewing Government Use of Kaspersky Software

    May 13, 2017

    Kaspersky Lab is stuck in the middle of a rather nasty fight between Washington and Moscow as the Russian-based anti-virus provider is being investigated by the US intelligence agencies. Following news that US officials were more and more concerned about how Russian spies could use Kaspersky’s software to spy on Americans and sabotage US systems, the ...

  • Wikileaks Unveils CIA’s Man-in-the-Middle Attack Tool

    May 5, 2017

    Wikileaks has published a new batch of the Vault 7 leak, detailing a man-in-the-middle (MitM) attack tool allegedly created by the United States Central Intelligence Agency (CIA) to target local networks. Since March, WikiLeaks has published thousands of documents and other secret tools that the whistleblower group claims came from the CIA. This latest batch is the ...