Executive brief
Cisco Secure Firewall Adaptive Security Appliance (ASA) and Threat Defense (FTD) are devices that protect networks by controlling which traffic is allowed through. A memory exhaustion bug in clustered deployments can cause access control rules to load incompletely, allowing attackers to send traffic that should be blocked directly into protected networks, bypassing security controls designed to keep intruders out.
Technical details
This vulnerability is a improper error handling issue (CWE-284) affecting clustered Cisco Secure Firewall ASA and FTD deployments. When a node joins a cluster and encounters memory exhaustion during access control list (ACL) replication, incomplete ACL rules are installed, resulting in either dropped legitimate traffic or permit of traffic that should be denied. An unauthenticated remote attacker can exploit this by sending traffic through the affected device to bypass access controls and reach protected internal networks. The attack requires the device to be deployed in a cluster configuration and to experience memory pressure during rule synchronization. Cisco has released software patches to address this vulnerability; no workarounds are available.
Affected products
- Cisco Secure Firewall Adaptive Security Appliance Software Multiple versions affected (see vendor advisory for specific ranges)
- Cisco Secure Firewall Threat Defense Software Multiple versions affected (see vendor advisory for specific ranges)
Timeline
- 2026-03-04: disclosed: Vulnerability disclosed by Cisco
- 2026-03-04: patched: Cisco released software updates to address this vulnerability