CISA: malware in Cisco firewalls survives patching

On 23 April, CISA published an update to an Emergency Directive concerning exploitation of CVE-2025-20333 and CVE-2025-20363 in Cisco Secure Firewall ASA and Cisco Secure Firewall Threat Defense. The vulnerabilities were originally disclosed and patched in September 2025. Recent findings show that the FIRESTARTER malware that exploited them can persist through device updates, which means patching was not sufficient mitigation. Cisco recommends checking for particular process names, while CISA recommends running the YARA rules from the FIRESTARTER report against core dumps. Organisations that were not compromised before patching need take no action.

What this means for your organisation

The directive targets US government bodies, but the same devices sit in Norwegian networks, not least at operators of critical infrastructure. The principle is what matters: a tick in the box marked "patched" says nothing about whether the device was clean when the patch went on. A firewall is also the last place you want a persistent intruder, since it sees all traffic and often terminates VPN access into the organisation.

Berigo recommends

  • Establish exactly when each ASA and FTD device was patched, and whether it was exposed in the period before that.
  • Run Cisco's recommended process name checks and CISA's YARA rules against core dumps on devices that were exposed.
  • If you find something, treat it as an incident rather than a maintenance item, and involve your response function.
  • Replace administrator passwords, certificates and VPN secrets on any device you cannot declare clean.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch