Remote Denial of Service in Cisco Secure Firewall Threat Defense Software
CVE-2026-20135
What is CVE-2026-20135?
A vulnerability exists in the TLS 1.3 implementation of Cisco Secure Firewall Threat Defense Software, allowing unauthenticated remote attackers to trigger unexpected device reloads, resulting in denial of service (DoS). The issue stems from improper buffer management during the TLS 1.3 connection lifecycle. An attacker can exploit this by sending a malformed TLS 1.3 packet to the listener socket of the affected system. A successful attack can lead to the termination of the LINA process, prompting the device to restart, which can disrupt both data and user-management traffic.
Affected Version(s)
Cisco Secure Firewall Threat Defense (FTD) Software 7.0.0
Cisco Secure Firewall Threat Defense (FTD) Software 7.0.0.1
Cisco Secure Firewall Threat Defense (FTD) Software 7.0.1