Junglewise Threat Intelligence

CVE-2026-20103: Cisco Secure Firewall ASA and FTD Remote Access SSL VPN denial of service

CVE-2026-20103 · Severity: high · CVSS 8.6 · Published 2026-03-04

Executive brief

Cisco Secure Firewall appliances (ASA and Threat Defense) used to protect enterprise networks include a remote access SSL VPN feature. A vulnerability in this VPN functionality allows unauthenticated attackers to send specially crafted packets that exhaust device memory, causing the VPN service to stop accepting new connections and rendering the appliance unable to respond to legitimate users seeking VPN access.

Technical details

The vulnerability stems from insufficient input validation in the Remote Access SSL VPN functionality of Cisco Secure Firewall ASA and Threat Defense (FTD) software. An unauthenticated, remote attacker can exploit this by sending crafted packets to the SSL VPN server, triggering memory exhaustion that results in denial of service. The attack vector is network-based with no authentication or user interaction required. A successful exploit prevents new VPN connections while potentially rendering the device web interface temporarily unresponsive, though management functions are not directly affected. Cisco has released software updates to address this vulnerability; no workarounds are available.

Affected products

  • Cisco Secure Firewall Adaptive Security Appliance (ASA) Software <UNKNOWN>
  • Cisco Secure Firewall Threat Defense (FTD) Software <UNKNOWN>

Timeline

  • 2026-03-04: disclosed: CVE-2026-20103 published
  • 2026-03-04: patched: Software updates released

References

Related threats