Logic Error in DNS over TCP for Cisco Secure Firewall ASA and FTD Software
CVE-2026-20248
6.8MEDIUM
What is CVE-2026-20248?
A logic error in the DNS over TCP implementation of Cisco Secure Firewall ASA and FTD Software allows unauthenticated attackers to exploit the TCP DNS response handler. By sending a specially crafted DNS reply, an attacker can trigger an unexpected restart of the device, leading to a denial of service (DoS) condition. This vulnerability requires the attacker to respond to DNS queries from the targeted device, either by controlling the DNS service or via a man-in-the-middle attack.
Affected Version(s)
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.16.1
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.16.1.28
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.16.2