Executive brief
Cisco Secure Firewall ASA and FTD are network security appliances that route traffic using the OSPF routing protocol. A vulnerability in OSPF packet processing could allow an attacker on an adjacent network to send malicious packets, causing the firewall to crash and become unavailable. This results in a denial of service that disrupts network traffic protection.
Technical details
CVE-2026-20020 is a buffer overflow vulnerability (CWE-119, CWE-787) in the OSPF protocol implementation of Cisco Secure Firewall ASA and FTD software. The vulnerability stems from insufficient input validation when processing OSPF update packets. An unauthenticated adjacent attacker can send crafted OSPF update packets to trigger a heap overflow, causing the affected device to reload and enter a denial-of-service (DoS) condition. If OSPF authentication is enabled, the attacker must know the authentication secret key. Cisco has released software updates; no workarounds are available.
Affected products
- Cisco Secure Firewall ASA Software <UNKNOWN>
- Cisco Secure Firewall Threat Defense Software <UNKNOWN>
Timeline
- 2026-03-04: disclosed