H-ISAC TLP White Vulnerability Advisory: New Attack Variant Targeting Cisco Secure Firewalls

H-ISAC TLP White Vulnerability Advisory: New Attack Variant Targeting Cisco Secure Firewalls (CVE-2025-20333 & CVE-2025-20362) 

November 6, 2025

 

On November 5, 2025, Cisco updated its security advisories regarding two critical vulnerabilities, CVE-2025-20333 and CVE-2025-20362, affecting Secure Firewall Adaptive Security Appliance (ASA) and Threat Defense (FTD) software, warning of a new, active attack variant.

This variant exploits both flaws to cause an unexpected device reload, resulting in a denial of service (DoS) condition on unpatched appliances. Cisco strongly recommends that users apply the released fixed software to prevent system compromise and service interruption.

Health-ISAC is sharing this to increase situational awareness and encourage organizations to assess their level of risk to these vulnerabilities.

View the detailed report below. 

For help with Cybersecurity and Risk Advisory Services exclusively for AHA members, contact:

John Riggi

National Advisor for Cybersecurity and Risk, AHA

jriggi@aha.org

(O) +1 202 626 2272