Executive brief
Cisco's Secure Firewall appliances (ASA and FTD software) contain a flaw in DTLS message handling that allows remote attackers to crash the firewall without authentication. An attacker can send specially crafted DTLS traffic to force the device to reload, disrupting all traffic protection and network operations until the firewall recovers. This affects organizations relying on these devices to protect corporate networks.
Technical details
The vulnerability is a resource management flaw (CWE-772) in DTLS message processing on Cisco Secure Firewall 3100 and 4200 Series devices when DTLS flow offload is enabled (default). An unauthenticated remote attacker can send a crafted stream of DTLS traffic to trigger improper resource handling, causing the affected device to reload. This is a network-reachable denial-of-service attack requiring no authentication or user interaction. Cisco has released software updates and identified a workaround (disabling DTLS flow offload via CLI) that trades DoS protection for reduced throughput and increased CPU utilization.
Affected products
- Cisco Secure Firewall ASA Software 9.22.3.191, 9.23.1.195, 9.24.1.155 (and other vulnerable versions prior to fixed releases 9.22.3.26, 9.23.1.211, 9.24.1.26)
- Cisco Secure Firewall Threat Defense Software Multiple versions on Secure Firewall 3100 and 4200 Series devices (see Cisco advisory for specific version details)
Timeline
- 2026-09-16: disclosed: Cisco Security Advisory published
- 2026-09-18: advisory: Advisory updated (version 1.1)