Junglewise Threat Intelligence

CVE-2026-20021: Cisco Secure Firewall ASA and FTD OSPF protocol denial of service

CVE-2026-20021 · Severity: medium · CVSS 4.3 · Published 2026-03-04

Technologies: Cisco Secure Firewall ASA Software, Cisco Secure Firewall Threat Defense Software. Vendors: Cisco.

Executive brief

Cisco Secure Firewall ASA and FTD software contain multiple vulnerabilities in the OSPF routing protocol implementation. An adjacent attacker, in some cases with knowledge of the OSPF authentication key, can send specially crafted packets to exhaust memory or cause heap corruption, forcing the firewall to reload and stopping all network traffic passing through it.

Technical details

Multiple input validation flaws exist in the OSPF protocol handler of Cisco Secure Firewall ASA and FTD software, affecting packet parsing in update packets and link-state messages. The vulnerabilities include buffer overflow (CWE-119), heap corruption (CWE-787), integer overflow (CWE-190), and improper input validation (CWE-20). Exploitation requires an adjacent attacker with network access to the OSPF service; authentication-required variants demand knowledge of the OSPF secret key. Successful exploitation causes memory exhaustion or heap corruption, leading to device reload and denial of service. Cisco has released software updates addressing these vulnerabilities; no workarounds are available.

Affected products

  • Cisco Secure Firewall ASA Software Multiple versions vulnerable; see Cisco advisory for specific affected releases
  • Cisco Secure Firewall Threat Defense Software Multiple versions vulnerable; see Cisco advisory for specific affected releases

Timeline

  • 2026-03-04: disclosed: Cisco Security Advisory cisco-sa-asaftd-ospf-ZH8PhbSW published
  • 2026-03-04: patched: Software updates released by Cisco

References

Related threats