CISA | Alerts
Follow
CISA Directs Federal Agencies to Identify and Mitigate Potential Compromise of Cisco Devices
CISA has issued Emergency Directive ED 25-03 concerning vulnerabilities in Cisco Adaptive Security Appliances and Firepower devices. Two specific vulnerabilities, CVE-2025-20333 and CVE-2025-20362, have been added to the Known Exploited Vulnerabilities Catalog. Federal agencies are mandated to immediately identify and mitigate any potential compromises. This requires them to locate all running instances of the affected Cisco devices, regardless of version. Agencies must also submit memory files to CISA for forensic analysis by September 26th. Detailed guidance and actions are available in the full Emergency Directive. Supplemental resources include instructions for core dumps and hunting, as well as an eviction strategies tool. The directive is aimed at federal agencies but all organizations are encouraged to review it. Both the UK's NCSC and Cisco have also released advisories and analysis related to these threats. Organizations should take proactive steps to address these critical vulnerabilities.