Executive brief
Cisco Secure Firewall Management Center (FMC) and Firewall Threat Defense (FTD) products contain a vulnerability in their inter-device communication protocol that allows remote attackers to crash affected devices by exhausting available memory. By sending specially crafted TLS connection frames, an unauthenticated attacker can trigger a denial-of-service condition that renders the security appliance unavailable.
Technical details
This vulnerability exists in the sftunnel inter-device communication protocol and results from improper memory resource management during TLS connection setup. An unauthenticated, remote attacker can exploit this by sending crafted sftunnel TLS frames to an affected device during the connection initialization phase. The vulnerability does not require authentication or user interaction; successful exploitation exhausts available memory on the target device, causing a denial-of-service condition. Cisco has released software updates to address this vulnerability, and no workarounds are available.
Affected products
- Cisco Secure Firewall Management Center <UNKNOWN>
- Cisco Secure Firewall Threat Defense <UNKNOWN>
Timeline
- 2026-09-16: disclosed