Junglewise Threat Intelligence

CVE-2026-20023: Cisco Secure Firewall ASA and FTD OSPF memory corruption denial of service

CVE-2026-20023 · Severity: medium · CVSS 6.1 · Published 2026-03-04

Executive brief

Cisco Secure Firewall devices (ASA and FTD) used to protect enterprise networks have a vulnerability in their OSPF protocol implementation. An attacker on the same network segment can send specially crafted packets that cause memory corruption, forcing the firewall to reboot and interrupting network traffic and security services until the device recovers.

Technical details

Multiple memory corruption vulnerabilities exist in the OSPF protocol parser of Cisco Secure Firewall ASA and FTD software, including buffer overflows and heap corruption issues (CWE-119, CWE-787, CWE-823). The vulnerabilities stem from insufficient input validation when processing OSPF update, link-state, and other protocol packets. Attack vectors vary: some require only network adjacency and are unauthenticated (CVE-2026-20020), while others require knowledge of the OSPF secret key (CVE-2026-20024, CVE-2026-20025). Successful exploitation causes memory corruption leading to unexpected device reboot and denial of service. Cisco has released patches; no workarounds are available.

Affected products

  • Cisco Secure Firewall Adaptive Security Appliance (ASA) Software affected versions running OSPF protocol (specific versions in Cisco advisory)
  • Cisco Secure Firewall Threat Defense (FTD) Software affected versions running OSPF protocol (specific versions in Cisco advisory)

Timeline

  • 2026-03-04: disclosed: Cisco Security Advisory published

References

Related threats