Executive brief
Cisco's Secure Firewall Adaptive Security Appliance (ASA) and Threat Defense (FTD) are network security devices that protect enterprise networks. A vulnerability in their EIGRP routing protocol implementation allows an unauthenticated attacker on the adjacent network to crash the firewall by sending malicious routing updates, causing a complete service outage until the device restarts.
Technical details
A memory leak vulnerability (CWE-401) exists in the EIGRP update message handler in Cisco Secure Firewall ASA and FTD software. An unauthenticated, adjacent attacker can exploit this by sending crafted EIGRP update messages at high rates to an affected device with EIGRP enabled. The improper resource management causes memory exhaustion, triggering an unexpected device reload and denial of service. The vulnerability requires network adjacency but no authentication, and affects multiple ASA and FTD releases. Cisco has released patched software versions for affected branches (9.20, 9.22, 9.23, 9.24).
Affected products
- Cisco Secure Firewall Adaptive Security Appliance (ASA) 9.20, 9.22, 9.23, 9.24 (see advisory for specific fixed versions)
- Cisco Secure Firewall Threat Defense (FTD) 7.4 and later (specific fixed versions in advisory)
Timeline
- 2026-09-16: disclosed: Cisco Security Advisory published
- 2026-09-18: advisory: Advisory updated (version 1.1 final)