Skip to content

Storm-1849/UAT4356 Exploiting Cisco ASA Secure Firewall Devices

Cisco ASA

Advanced persistent threat Critical RCE and persistent access ArcaneDoor campaign

Overview

Since May 2025, advanced Chinese threat actor Storm-1849 (UAT4356) has actively scanned and exploited Cisco ASA Secure Firewalls (including 5500-X Series running ASA/FTD software) across U.S., European, and Asian government, defense, and financial networks. The actors leverage critical VPN Web Server vulnerabilities to compromise edge appliances, maintain persistent access (even after reboot/upgrades), and manipulate infrastructure.

Technical Details

  • CVE-2025-20333: Buffer overflow (CWE-120), VPN Web Server; enables authenticated root RCE if exploited. (CVSS 9.9)
  • CVE-2025-20362: URL path normalization flaw; allows unauthenticated login bypass and access to WebVPN endpoints. (CVSS 6.5)
  • CVE-2025-20363: Web Service RCE (not yet exploited). (CVSS 9.0)
  • Campaign: ArcaneDoor lineage, persistent malware (RayInitiator bootkit, LINE VIPER shellcode loader).
  • Chaining: CVE-2025-20362 is unauthenticated; attackers chain with CVE-2025-20333 to achieve RCE without credentials.
  • Affected Products: ASA Software (branches 9.16–9.22), FTD (7.0–7.6); VPN Web Server

Attack Scenario

  • Chinese hackers scan, fingerprint, and exploit vulnerable ASA edge firewalls.
  • Chained exploitation bypasses VPN authentication and conducts RCE.
  • Persistent malware (RayInitiator/LINE VIPER) survives reboots and upgrades, allowing attackers to retain access.
  • Targets: U.S. military, federal and state agencies, India, EU, UAE, Africa, and numerous critical infrastructure IPs.

Impact Assessment

  • Persistent access to government/defense and financial sector firewalls
  • Remote command execution, data exfiltration, and manipulation
  • Disruption and espionage risk, supply chain compromise
  • Ability to survive patching and device upgrades if exploitation precedes remediation

Mitigation Strategies

  • Immediate patching to ASA/FTD versions listed in Cisco advisories
  • Disable unnecessary WebVPN endpoints and services
  • Monitor all ASA edge logs for anomalous authentication and session creation
  • Reboot and upgrade to ensure malware removal; verify bootkit absence
  • Implement network segmentation for critical assets
  • Follow CISA Emergency Directive ED 25-03 requirements

Resources