Executive brief
A vulnerability in Cisco's firewall software could allow an attacker on the same local network to crash the device. This affects the OSPF routing protocol, which is used to manage network traffic paths. If exploited, the firewall will restart unexpectedly, causing a temporary loss of network connectivity and security protection.
Technical details
The vulnerability exists in the OSPF protocol implementation of Cisco ASA and FTD software due to insufficient input validation when processing OSPF link-state update (LSU) packets. An authenticated, adjacent attacker with knowledge of the OSPF secret key can send crafted LSU packets to trigger an integer overflow (CWE-190) and subsequent heap corruption. This corruption leads to an unexpected device reload, resulting in a denial of service (DoS) condition. The vulnerability is reachable via the adjacent network (Layer 2) and requires valid OSPF authentication credentials if enabled. Cisco has released software updates to address this issue; no workarounds are available.
Affected products
- Cisco Adaptive Security Appliance (ASA) Software 9.12.1 to 9.16.4.85, 9.17.1 to 9.18.4.66, 9.19.1 to 9.20.4, 9.22.1.1 to 9.22.2.4, 9.23.1 to 9.23.1.7
- Cisco Firepower Threat Defense (FTD) Software 6.4.0 to 7.0.9, 7.1.0 to 7.2.11, 7.3.0 to 7.4.3, 7.6.0 to 7.6.4, 7.7.0 to 7.7.11
Timeline
- 2026-03-04: advisory: Initial publication by Cisco
- 2026-03-04: disclosed
- 2026-06-05: other: NVD analysis and CPE information updated