Denial of Service Vulnerability in Cisco Secure Firewall Products
CVE-2026-20250

8.6HIGH

What is CVE-2026-20250?

A vulnerability exists in the Datagram TLS (DTLS) message handling of Cisco Secure Firewall Adaptive Security Appliance and Threat Defense Software. This issue affects the Cisco Secure Firewall 3100 and 4200 Series devices, allowing an unauthenticated remote attacker to exploit the improper resource management in processing DTLS messages. By sending a crafted DTLS traffic stream to an affected device, an attacker may trigger a denial of service condition, causing the device to reload and potentially disrupt network services.

Affected Version(s)

Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.23.1

Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.22.1.1

Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.22.1.3

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.