Executive brief
Cisco Secure Firewall ASA and Threat Defense (FTD) devices can be remotely attacked without authentication by flooding TCP SYN packets, which triggers excessive logging and consumes CPU resources. When syslog is enabled (the default configuration), this attack causes the device to become unresponsive, disrupting network traffic and security services that protect the organization's perimeter.
Technical details
This vulnerability (CWE-835: Infinite Loop) stems from improper rate limiting of syslog message 419002 in Cisco Secure Firewall ASA and FTD software. An unauthenticated remote attacker can exploit this by sending a flood of TCP SYN packets to an affected device. The attack vector is network-based with no prerequisites, as the vulnerability is triggered when syslog logging is globally enabled (default configuration) and message 419002 is at an active logging level. A successful exploit causes high CPU utilization and performance degradation, resulting in denial of service. Cisco has released software updates and identified workarounds to mitigate the vulnerability.
Affected products
- Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
- Cisco Secure Firewall Threat Defense (FTD) Software
Timeline
- 2026-09-16: disclosed: Vulnerability publicly disclosed by Cisco Security Advisory cisco-sa-asa-ftd-logging-dos-ZXXNesfN
- 2026-09-18: other: Advisory updated with final information