Junglewise Threat Intelligence

CVE-2026-20105: Cisco Secure Firewall ASA and FTD Remote Access SSL VPN denial of service

CVE-2026-20105 · Severity: high · CVSS 7.7 · Published 2026-03-04

Executive brief

Cisco Secure Firewall ASA and FTD appliances used to protect enterprise networks against threats include Remote Access SSL VPN functionality that authenticates remote employees. A flaw in how these devices handle VPN traffic allows a remote attacker to send specially crafted packets that exhaust device memory, forcing the appliance to reload and disrupting network connectivity and remote access for all users until it recovers.

Technical details

The vulnerability exists in the Remote Access SSL VPN functionality of Cisco Secure Firewall ASA and FTD software due to insufficient input validation (CWE-120, CWE-330, CWE-401, CWE-770). An authenticated remote attacker with a valid VPN connection can send crafted packets to the SSL VPN server, triggering uncontrolled memory consumption. The attack requires network reachability to the VPN endpoint and a valid VPN authentication, but no further user interaction. Successful exploitation causes the device to reload, resulting in a denial of service condition that may require manual intervention to restore service. Cisco has released software updates to address these vulnerabilities; no workarounds are available.

Affected products

  • Cisco Secure Firewall Adaptive Security Appliance (ASA) Software Multiple versions (see Cisco advisory for specific affected releases)
  • Cisco Secure Firewall Threat Defense (FTD) Software Multiple versions (see Cisco advisory for specific affected releases)

Timeline

  • 2026-03-04: disclosed

References

Related threats