Junglewise Threat Intelligence

CVE-2026-20022: Cisco Secure Firewall ASA and FTD OSPF DoS via insufficient input validation

CVE-2026-20022 · Severity: medium · CVSS 6.1 · Published 2026-03-04

Technologies: Cisco Secure Firewall ASA Software, Cisco Secure Firewall Threat Defense Software. Vendors: Cisco.

Executive brief

Cisco Secure Firewall ASA and FTD devices, which protect enterprise networks by routing traffic securely, contain multiple vulnerabilities in their OSPF (routing protocol) implementation. An attacker on the same network segment can send specially crafted packets to force these devices to crash unexpectedly, disrupting all network traffic that depends on them and leaving organizations unable to route traffic or enforce security policies.

Technical details

Multiple vulnerabilities exist in the OSPF protocol processing of Cisco Secure Firewall ASA and FTD Software due to insufficient input validation and heap corruption when parsing OSPF packets (CVE-2026-20020, CVE-2026-20021, CVE-2026-20022, CVE-2026-20023, CVE-2026-20024, CVE-2026-20025). The vulnerabilities include buffer overflows, heap corruption, and out-of-bounds memory writes when processing crafted OSPF update and link-state update packets. CVE-2026-20022 specifically can be triggered by an unauthenticated adjacent attacker when OSPF canonicalization debug is enabled; other variants require OSPF authentication. An adjacent attacker can exploit these by sending malformed OSPF packets, causing the affected device to reload and resulting in a denial of service. Cisco has released software updates to address these vulnerabilities; no workarounds are available.

Affected products

  • Cisco Secure Firewall ASA Software Multiple versions affected; see vendor advisory for specific vulnerable releases
  • Cisco Secure Firewall Threat Defense Software Multiple versions affected; see vendor advisory for specific vulnerable releases

Timeline

  • 2026-03-04: disclosed: Cisco Security Advisory published

References

Related threats