Skip to content

CVE-2026-20222

Cisco ASA and FTD EIGRP denial of service lets adjacent attackers reload devices (CVE-2026-20222)

High 7.4 Vendor: Cisco Published

Cisco Secure Firewall ASA and FTD Software have a high-severity EIGRP denial-of-service vulnerability (CVSS 7.4). An unauthenticated adjacent attacker can cause repeated device reloads. Apply Cisco's fixed software and enable EIGRP authentication as mitigation.

What happened

An unauthenticated attacker on an adjacent network segment can send crafted EIGRP update messages at a high rate to an affected Cisco Secure Firewall ASA or Threat Defense device. The EIGRP implementation does not manage resources correctly when it handles those messages, which causes a memory leak. Over time the device exhausts memory and reloads unexpectedly. The attacker needs no credentials and no user interaction, but must already be on a network position adjacent to the device. The impact is availability only: the device goes offline until it restarts. Cisco PSIRT has said it is not aware of any public announcements or malicious use of this vulnerability.

Who is affected

Cisco Secure Firewall ASA Software and Cisco Secure Firewall Threat Defense (FTD) Software are firewall and threat-defence platforms commonly deployed at network perimeters, VPN termination points and internal segmentation boundaries. A device is exposed only if EIGRP is enabled. The affected releases listed by Cisco include ASA 9.19.1, 9.19.1.5, 9.19.1.9, 9.19.1.12, 9.19.1.18, 9.19.1.22, 9.20.1 and 9.20.1.5; and FTD 7.3.0, 7.3.1, 7.3.1.1, 7.3.1.2, 7.4.0, 7.4.1, 7.4.1.1 and 7.6.0.

What to do now

  1. Apply Cisco's fixed software for your ASA or FTD version train. Cisco states fixed software is available; do not remain on an affected release.
  2. If you cannot patch immediately, enable EIGRP authentication throughout the network. Cisco notes that no workarounds fully address the vulnerability, but this mitigation reduces the risk of successful exploitation. Evaluate it in your own environment before deploying, since authentication changes can affect EIGRP peering.

How to detect it

Cisco has not published indicators of compromise for this vulnerability. Because successful exploitation causes a memory leak and an eventual reload, monitor ASA and FTD devices that run EIGRP for unexpected reload events and for steadily increasing memory consumption that is not explained by normal traffic. A device that reloads repeatedly without a scheduled change should be investigated.

Beyond the patch

Beyond the patch, this is a vendor-software risk in the network's most critical path. Supply Chain Defense & Third-Party Risk helps maintain visibility of advisory and patch status across Cisco and other infrastructure vendors, so the next EIGRP-class issue is caught before it becomes an outage. Managed Detection & Response (MDR) can watch for the device instability that follows an attempt to trigger this denial of service.

Affected and fixed versions

ProductAffectedFixed in
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software9.19.1
9.19.1.5
9.19.1.9
9.19.1.12
9.19.1.18
9.20.1
9.19.1.22
9.20.1.5
No fixed version listed yet
Cisco Secure Firewall Threat Defense (FTD) Software7.3.0
7.3.1
7.3.1.1
7.4.0
7.4.1
7.4.1.1
7.3.1.2
7.6.0
No fixed version listed yet

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.