Executive brief
Cisco Secure Firewall appliances (ASA and FTD models) contain a flaw in their DNS over TCP handling that allows a remote attacker to crash the device. An attacker who can intercept or control DNS responses can send a specially crafted reply that causes the DNS response handler to restart, forcing a full device reload. This results in a complete service outage until the appliance recovers, affecting all traffic passing through the firewall.
Technical details
The vulnerability stems from a logic error in the DNS over TCP implementation when parsing DNS queries and tracking incoming buffer sizes (CWE-195). An unauthenticated, remote attacker can exploit this by crafting a malicious DNS response to a query originated by the target device. The attacker must be positioned to respond to the device's DNS queries, either through DNS server compromise or man-in-the-middle positioning (high complexity attack condition). Successful exploitation causes the TCP DNS response handler to crash and restart, forcing the entire appliance to reload and triggering a denial of service. Software patches are available for all affected releases.
Affected products
- Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.16 and earlier, 9.18 before 9.18.4.94, 9.20 before 9.20.4.49, 9.22 before 9.22.3.26, 9.23 before 9.23.1.47, 9.24 before 9.24.1.26
- Cisco Secure Firewall Threat Defense (FTD) Software 7.0 and earlier, 7.2 before 7.2.12, 7.4 before 7.4.8, 7.6 before 7.6.6, 7.7 before 7.7.13, 10.0 before 10.0.2, 10.1 before 10.1.0
Timeline
- 2026-09-16: disclosed: Vulnerability disclosed by Cisco
- 2026-09-16: patched: Fixed software releases available