Executive Summary
In early 2024, Cisco disclosed four actively exploited zero-day vulnerabilities impacting its firewalls and IOS software, affecting millions of devices globally. At least three of these flaws were exploited by a sophisticated nation-state threat actor behind the ArcaneDoor campaign. Attackers leveraged the zero-days to gain unauthorized access to networks, facilitating lateral movement, data interception, and potentially persistent backdoors in affected systems. The campaign specifically targeted high-value government and critical infrastructure entities, prompting urgent patching initiatives.
This incident underscores a growing trend of state-backed actors aggressively targeting network infrastructure with zero-day exploits. As attackers focus on networking gear as an entry point, organizations must reevaluate perimeter defenses and accelerate patch management to remain resilient against such advanced threats.
Why This Matters Now
Cisco’s zero-day vulnerabilities are being actively exploited in the wild by nation-state actors and highlight the urgent need to patch critical network infrastructure. With the ongoing focus on firewalls and routers as primary targets, organizations are at increased risk of data breach and operational disruption if immediate action is not taken.
Attack Path Analysis
Attackers exploited unpatched Cisco zero-day vulnerabilities to gain initial access to firewall and network devices. Following compromise, they leveraged device-level access to escalate privileges, installing backdoors or manipulating system configurations. They then moved laterally across the internal network, bypassing traditional network segmentation boundaries. The attackers established command and control channels, potentially using encrypted or covert communications to maintain persistent access. Sensitive data was exfiltrated through egress paths, possibly leveraging allowed outbound connections or VPN tunnels. The ultimate impact included possible disruption of network operations, data theft, and exposure of confidential information.
Kill Chain Progression
Initial Compromise
Description
Attackers exploited Cisco zero-day vulnerabilities in firewalls and IOS devices to gain initial access to network infrastructure.
Related CVEs
CVE-2025-20333
CVSS 9.9A critical remote code execution vulnerability in Cisco ASA and FTD software, allowing unauthenticated attackers to execute arbitrary code.
Affected Products:
Cisco Adaptive Security Appliance (ASA) – 9.12 up to 9.12.4.65, 9.14 up to 9.14.4.23, 9.15 up to 9.15.1.21
Cisco Firepower Threat Defense (FTD) – 7.0.8.1, 7.4.2.4, 7.6.1
Exploit Status:
exploited in the wildCVE-2025-20362
CVSS 6.5A medium-severity privilege escalation vulnerability in Cisco ASA and FTD software, allowing attackers to gain higher-level access on compromised systems.
Affected Products:
Cisco Adaptive Security Appliance (ASA) – 9.12 up to 9.12.4.65, 9.14 up to 9.14.4.23, 9.15 up to 9.15.1.21
Cisco Firepower Threat Defense (FTD) – 7.0.8.1, 7.4.2.4, 7.6.1
Exploit Status:
exploited in the wildCVE-2025-20363
CVSS 9A high-severity command execution vulnerability in Cisco ASA and FTD software, facilitating control over affected devices.
Affected Products:
Cisco Adaptive Security Appliance (ASA) – 9.12 up to 9.12.4.65, 9.14 up to 9.14.4.23, 9.15 up to 9.15.1.21
Cisco Firepower Threat Defense (FTD) – 7.0.8.1, 7.4.2.4, 7.6.1
Exploit Status:
exploited in the wildCVE-2025-20352
CVSS 7.7A critical SNMP vulnerability in Cisco IOS and IOS XE software, allowing authenticated remote code execution or denial of service.
Affected Products:
Cisco IOS – 15.2 up to 15.2(4)M9
Cisco IOS XE – 16.9 up to 16.9.6
Exploit Status:
exploited in the wildCVE-2025-20393
CVSS 10A critical zero-day vulnerability in Cisco AsyncOS Software for Secure Email Gateway and Secure Email and Web Manager, allowing attackers to execute arbitrary commands with root privileges.
Affected Products:
Cisco Secure Email Gateway – All versions of AsyncOS
Cisco Secure Email and Web Manager – All versions of AsyncOS
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Hardware Additions
Exploitation of Remote Services
Network Sniffing
Impair Defenses
Valid Accounts
Data from Local System
Exfiltration Over C2 Channel
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Security of System Components Against Known Vulnerabilities
Control ID: 6.3.1
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.05
DORA – ICT Risk Management Framework
Control ID: Art. 9
CISA ZTMM 2.0 – Automated Vulnerability and Patch Management
Control ID: Pillar: Device, Capability: Vulnerability Management
NIS2 Directive – Technical and Organizational Measures
Control ID: Art. 21(2)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer/Network Security
Zero-day exploitation of Cisco firewalls and IOS creates critical infrastructure vulnerabilities, compromising network segmentation and threat detection capabilities across security implementations.
Telecommunications
Nation-state ArcaneDoor campaign targeting Cisco devices threatens core network infrastructure, potentially disrupting encrypted traffic flows and east-west traffic security controls.
Financial Services
Actively exploited Cisco zero-days compromise PCI compliance requirements, threatening egress security policies and multicloud visibility controls protecting sensitive financial data.
Government Administration
Nation-state exploitation of millions of Cisco devices poses severe risks to government networks, undermining zero trust segmentation and encrypted communications infrastructure.
Sources
- Cisco's Wave of Actively Exploited Zero-Day Bugs Targets Firewalls, IOShttps://www.darkreading.com/vulnerabilities-threats/cisco-actively-exploited-zero-day-bugs-firewalls-iosVerified
- CISA Urges Immediate Patching as ArcaneDoor Hackers Exploit Three Cisco Zero-Day Vulnerabilitieshttps://www.clearphish.ai/news/cisa-urgent-directive-cisco-zero-day-arcanedoor-espionage-2025Verified
- Cisco ASA Zero-Day Exploit: ArcaneDoor Campaign Deep Divehttps://www.protoslabs.io/resources/deep-dive-cisco-asa-zero-day-exploit-campaign-arcanedoor-uat4356-storm-1849Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Implementing Zero Trust Segmentation, east-west traffic controls, threat detection, and robust egress filtering would have constrained attacker movement, provided real-time visibility, and prevented exploitation and data exfiltration. CNSF-aligned controls enforce least privilege, limit lateral movement, and ensure encrypted traffic and policy enforcement even if perimeter devices are breached.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Inline real-time inspection could detect and block anomalous or malicious traffic targeting vulnerable devices.
Control: Threat Detection & Anomaly Response
Mitigation: Detection of privilege escalation attempts triggers alerts for rapid response.
Control: Zero Trust Segmentation
Mitigation: Prevents unauthorized east-west movement between workloads and network segments.
Control: Egress Security & Policy Enforcement
Mitigation: Blocks unauthorized outbound connections to attacker infrastructure.
Control: Egress Security & Policy Enforcement
Mitigation: Detects and blocks data exfiltration attempts through outbound traffic monitoring.
Rapid detection and visibility into ongoing or attempted destructive actions reduce business impact.
Impact at a Glance
Affected Business Functions
- Network Security
- Email Communication
- Web Management
Estimated downtime: 7 days
Estimated loss: $500,000
Potential exposure of sensitive email communications and network configurations due to unauthorized access and control over security appliances.
Recommended Actions
Key Takeaways & Next Steps
- • Prioritize immediate patching of network infrastructure devices to mitigate known vulnerabilities.
- • Deploy Zero Trust Segmentation and east-west controls to limit lateral attacker movement if perimeter defenses fail.
- • Enforce centralized, granular egress policies to tightly control outbound data flows and detect exfiltration attempts.
- • Integrate advanced threat detection and anomaly response tools for real-time visibility and faster incident response.
- • Utilize cloud-native, fabric-based security controls for consistent policy enforcement and observability across all network segments.



