Executive brief
Cisco Secure Firewall Threat Defense (FTD) is a network security appliance that inspects encrypted traffic to detect threats. A flaw in its SSL decryption feature causes the device to crash when it receives specially crafted TLS 1.2 encrypted traffic, resulting in a denial of service that disrupts network security protection and business operations. No workaround is available; devices require a software patch to fix the issue.
Technical details
This vulnerability is a memory management flaw (CWE-404) in the Do Not Decrypt exclusion feature of the SSL decryption engine affecting TLS 1.2 traffic inspection. An unauthenticated remote attacker can exploit it by sending crafted TLS 1.2 encrypted packets through the device without requiring authentication or user interaction. The attack results in improper memory handling that causes a device reload, achieving denial of service. The vulnerability only affects TLS 1.2; other TLS versions are not impacted. Cisco has released software patches to address the vulnerability, and no workarounds are available.
Affected products
- Cisco Secure Firewall Threat Defense Multiple releases (see Cisco Software Checker for affected versions)
Timeline
- 2026-03-04: disclosed
- 2026-03-04: patched: Cisco released software updates on the publication date