Somebody’s going to have to ELI5 me on this one, as the article contradicts itself (same result, though: anybody who remotely connects to ASA’s would be affected).
The first paragraph talks about software, with the implication it’s the VPN client. The remaining paragraphs show there’s a vulnerability with Cisco’s ASAs, which are *hardware* (and aren’t used only for VPNs, but I’m guessing the vulnerability is in the VPN part of the ASA firmware).
Could someone with a stronger SecOps or related experience level please clarify?
More accurate would be to say that this impacts all businesses that *do not* fully isolate their corporate intranet from the wider internet. Anyone running a CISCO device should view the above link, regardless of whether they have remote workers employed.
3 Kommentare
Somebody’s going to have to ELI5 me on this one, as the article contradicts itself (same result, though: anybody who remotely connects to ASA’s would be affected).
The first paragraph talks about software, with the implication it’s the VPN client. The remaining paragraphs show there’s a vulnerability with Cisco’s ASAs, which are *hardware* (and aren’t used only for VPNs, but I’m guessing the vulnerability is in the VPN part of the ASA firmware).
Could someone with a stronger SecOps or related experience level please clarify?
It’s weird to claim this is *specifically* impacting remote workers. There’s no need to include that in the warning, [when it impacts hardware devices that are probably not in most remote workers‘ homes](https://www.cyber.gc.ca/en/alerts-advisories/al25-012-vulnerabilities-impacting-cisco-asa-ftd-devices-cve-2025-20333-cve-2025-20362-cve-2025-20363).
More accurate would be to say that this impacts all businesses that *do not* fully isolate their corporate intranet from the wider internet. Anyone running a CISCO device should view the above link, regardless of whether they have remote workers employed.
*Edit:*[ bonus hold music link](https://www.youtube.com/watch?v=nLpm4aysr8I) *for those who wish to know what their IT staff are bound to experience today.*
The company famous for leaving back doors in their equipement is suffering from remote attacks? I am shocked good sir!