Skip to content

CVE-2026-20250

Cisco Secure Firewall ASA and FTD DTLS denial of service allows unauthenticated remote attackers to reload affected devices (CVE-2026-20250)

High 8.6 Vendor: Cisco Published

Cisco Secure Firewall ASA and FTD software on Firepower 3100 and 4200 series has a network-reachable DTLS denial-of-service flaw. Unauthenticated attackers can send crafted DTLS traffic to reload the device. Cisco indicates a fix is available, and a workaround disables DTLS flow offload.

What happened

An unauthenticated, remote attacker can cause a denial of service on affected Cisco Secure Firewall ASA and FTD software running on Firepower 3100 and 4200 series devices. The flaw is in Datagram TLS (DTLS) message handling: improper resource management when processing certain DTLS messages. An attacker can exploit it by sending a crafted stream of DTLS traffic to an affected device.

A successful exploit can cause the device to reload. Cisco rates this high severity with CVSS 3.1 score 8.6 (AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H). Cisco PSIRT is not aware of any public announcements or malicious use of the vulnerability described in the advisory.

Who is affected

The advisory names the following releases: Cisco Secure Firewall ASA Software versions 9.23.1, 9.22.1.1, 9.22.1.3, 9.22.1.6, 9.22.2, 9.23.1.3, 9.22.2.4 and 9.23.1.7; and Cisco Secure Firewall FTD Software versions 7.6.0, 7.7.0, 7.6.1, 7.6.2, 7.7.10, 7.7.11, 7.6.2.1 and 7.7.10.1. The issue applies to Cisco Secure Firewall 3100 Series and 4200 Series devices. These are firewall and threat defence platforms. The advisory does not state a specific feature that exposes the DTLS handling, only that crafted DTLS traffic to the device is required.

What to do now

  1. Confirm whether you run one of the affected ASA or FTD releases on Firepower 3100 or 4200 series devices.
  2. Apply Cisco's fix. Cisco has indicated a fix is available, but no specific fixed releases are listed in the data provided here; refer to Cisco's advisory for the applicable update.
  3. If you cannot patch immediately, apply the vendor workaround: use the no flow-offload-dtls CLI command to disable DTLS flow offload. On FTD, push this command using FlexConfig. This moves DTLS-encrypted traffic to software processing and may reduce throughput and increase CPU utilization, particularly with high DTLS session volumes. Test in your own environment before deployment.
  4. Where possible, restrict network access to the DTLS service on affected devices and monitor for unplanned reloads.

How to detect it

The advisory does not provide indicators of compromise. The visible symptom of successful exploitation would be an unplanned reload or loss of availability on an affected Firepower 3100 or 4200 device. If the workaround is applied, increased CPU utilization is expected and should not be read as evidence of exploitation.

Beyond the patch

Beyond applying the fix and workaround, this CVE reinforces the need to inventory network-exposed security appliances and track third-party software versions. Virtual CISO Services (vCISO) helps identify and harden services reachable without credentials, and Supply Chain Defense & Third-Party Risk tracks vendor platforms such as Cisco ASA and FTD so affected releases are flagged before they create exposure.

Affected and fixed versions

ProductAffectedFixed in
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software9.23.1
9.22.1.1
9.22.1.3
9.22.1.6
9.22.2
9.23.1.3
9.22.2.4
9.23.1.7
No fixed version listed yet
Cisco Secure Firewall Threat Defense (FTD) Software7.6.0
7.7.0
7.6.1
7.6.2
7.7.10
7.7.11
7.6.2.1
7.7.10.1
No fixed version listed yet

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.