Junglewise Threat Intelligence

CVE-2026-20154: Cisco Secure Firewall ASA/FTD denial of service in syslog rate limiting

CVE-2026-20154 · Severity: high · CVSS 8.6 · Published 2026-09-16

Executive brief

Cisco Secure Firewall ASA and Threat Defense (FTD) devices can be remotely attacked without authentication by flooding TCP SYN packets, which triggers excessive logging and consumes CPU resources. When syslog is enabled (the default configuration), this attack causes the device to become unresponsive, disrupting network traffic and security services that protect the organization's perimeter.

Technical details

This vulnerability (CWE-835: Infinite Loop) stems from improper rate limiting of syslog message 419002 in Cisco Secure Firewall ASA and FTD software. An unauthenticated remote attacker can exploit this by sending a flood of TCP SYN packets to an affected device. The attack vector is network-based with no prerequisites, as the vulnerability is triggered when syslog logging is globally enabled (default configuration) and message 419002 is at an active logging level. A successful exploit causes high CPU utilization and performance degradation, resulting in denial of service. Cisco has released software updates and identified workarounds to mitigate the vulnerability.

Affected products

  • Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
  • Cisco Secure Firewall Threat Defense (FTD) Software

Timeline

  • 2026-09-16: disclosed: Vulnerability publicly disclosed by Cisco Security Advisory cisco-sa-asa-ftd-logging-dos-ZXXNesfN
  • 2026-09-18: other: Advisory updated with final information

References

Related threats