Junglewise Threat Intelligence

CVE-2026-20024: Cisco ASA and FTD Software heap corruption in OSPF protocol

CVE-2026-20024 · Severity: medium · CVSS 6.8 · Published 2026-03-04

Executive brief

Cisco Secure Firewall ASA and FTD software, which are used to protect corporate networks and manage traffic, contain a vulnerability in their OSPF routing protocol. An attacker who has already gained access to the local network and obtained the OSPF secret key could send malicious traffic to the firewall. This would cause the device to crash and restart, leading to a complete network outage (Denial of Service) for users relying on that firewall.

Technical details

A heap corruption vulnerability exists in the OSPF protocol implementation of Cisco ASA and FTD software. The flaw is triggered during the parsing of OSPF packets. An attacker located on the same adjacent network segment who possesses the OSPF secret key can exploit this by sending crafted OSPF packets to the service. Successful exploitation leads to heap memory corruption, causing the device to reload and resulting in a denial of service (DoS). Cisco has released software updates to address this issue, and no workarounds are currently available.

Affected products

  • Cisco Secure Firewall ASA Software
  • Cisco Secure Firewall Threat Defense (FTD) Software

Timeline

  • 2026-03-04: advisory: Initial publication by Cisco
  • 2026-03-04: disclosed

References

Related threats