Hazard

Is CVE-2023-20269 being exploited?

Ransomware crews are using this

CISA has linked this vulnerability to known ransomware campaigns. Treat any exposed instance as an active incident, not a patching ticket.

Cisco Adaptive Security Appliance and Firepower Threat Defense Unauthorized Access Vulnerability

Cisco · Adaptive Security Appliance and Firepower Threat Defense

CVSS 5 EPSS 22% no public exploit indexed ransomware Fix deadline passed 4 October 2023

What it is

Cisco Adaptive Security Appliance and Firepower Threat Defense contain an unauthorized access vulnerability that could allow an unauthenticated, remote attacker to conduct a brute force attack in an attempt to identify valid username and password combinations or establish a clientless SSL VPN session with an unauthorized user.

Why we say that

  • Linked by CISA to known ransomware campaigns
  • CISA's federal remediation deadline (2023-10-04) has passed
  • Listed in the CISA Known Exploited Vulnerabilities catalogue

Every line above comes from a named public source. Where the evidence is thin, we say so rather than inventing confidence — see methodology.

What to do

Apply mitigations per vendor instructions for group-lock and vpn-simultaneous-logins or discontinue use of the product for unsupported devices.

What it costs when this goes wrong

This is where UK enforcement meets the vulnerability record. This vulnerability is used in ransomware campaigns; here is what ransomware has cost UK organisations at the regulator.

All UK cases caused by ransomware →