Executive brief
Cisco Secure Firewall devices (ASA and Threat Defense) include a SAML 2.0 single sign-on feature used to authenticate remote VPN users. A flaw in the SAML message processing can be exploited by an attacker to send specially crafted messages that cause the device to unexpectedly reload, taking the firewall offline and disrupting all VPN and network traffic it protects.
Technical details
The vulnerability exists in the SAML 2.0 SSO authentication component of Cisco Secure Firewall ASA and FTD software due to insufficient error checking when processing SAML protocol messages. An unauthenticated, remote attacker can exploit this via the network by sending malformed SAML messages to the affected SAML service without requiring any credentials or user interaction. A successful exploit causes the device to reload unexpectedly, resulting in a denial of service condition that may require manual intervention to restore. The CVSS 3.1 base score is 8.6 (AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H), reflecting the network attack vector, lack of authentication, high availability impact, and scope change. Patches are available from Cisco.
Affected products
- Cisco Secure Firewall ASA Software Affected versions available in Cisco advisory; see fixed software section
- Cisco Secure Firewall Threat Defense Software Affected versions available in Cisco advisory; see fixed software section
Timeline
- 2026-03-04: disclosed: Cisco Security Advisory published
- 2026-03: patched: Software updates available from Cisco