CVE-2026-20250
Cisco Secure Firewall ASA and FTD DTLS denial of service allows unauthenticated remote attackers to reload affected devices (CVE-2026-20250)
Cisco Secure Firewall ASA and FTD software on Firepower 3100 and 4200 series has a network-reachable DTLS denial-of-service flaw. Unauthenticated attackers can send crafted DTLS traffic to reload the device. Cisco indicates a fix is available, and a workaround disables DTLS flow offload.
What happened
An unauthenticated, remote attacker can cause a denial of service on affected Cisco Secure Firewall ASA and FTD software running on Firepower 3100 and 4200 series devices. The flaw is in Datagram TLS (DTLS) message handling: improper resource management when processing certain DTLS messages. An attacker can exploit it by sending a crafted stream of DTLS traffic to an affected device.
A successful exploit can cause the device to reload. Cisco rates this high severity with CVSS 3.1 score 8.6 (AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H). Cisco PSIRT is not aware of any public announcements or malicious use of the vulnerability described in the advisory.
Who is affected
The advisory names the following releases: Cisco Secure Firewall ASA Software versions 9.23.1, 9.22.1.1, 9.22.1.3, 9.22.1.6, 9.22.2, 9.23.1.3, 9.22.2.4 and 9.23.1.7; and Cisco Secure Firewall FTD Software versions 7.6.0, 7.7.0, 7.6.1, 7.6.2, 7.7.10, 7.7.11, 7.6.2.1 and 7.7.10.1. The issue applies to Cisco Secure Firewall 3100 Series and 4200 Series devices. These are firewall and threat defence platforms. The advisory does not state a specific feature that exposes the DTLS handling, only that crafted DTLS traffic to the device is required.
What to do now
- Confirm whether you run one of the affected ASA or FTD releases on Firepower 3100 or 4200 series devices.
- Apply Cisco's fix. Cisco has indicated a fix is available, but no specific fixed releases are listed in the data provided here; refer to Cisco's advisory for the applicable update.
- If you cannot patch immediately, apply the vendor workaround: use the
no flow-offload-dtlsCLI command to disable DTLS flow offload. On FTD, push this command using FlexConfig. This moves DTLS-encrypted traffic to software processing and may reduce throughput and increase CPU utilization, particularly with high DTLS session volumes. Test in your own environment before deployment. - Where possible, restrict network access to the DTLS service on affected devices and monitor for unplanned reloads.
How to detect it
The advisory does not provide indicators of compromise. The visible symptom of successful exploitation would be an unplanned reload or loss of availability on an affected Firepower 3100 or 4200 device. If the workaround is applied, increased CPU utilization is expected and should not be read as evidence of exploitation.
Beyond the patch
Beyond applying the fix and workaround, this CVE reinforces the need to inventory network-exposed security appliances and track third-party software versions. Virtual CISO Services (vCISO) helps identify and harden services reachable without credentials, and Supply Chain Defense & Third-Party Risk tracks vendor platforms such as Cisco ASA and FTD so affected releases are flagged before they create exposure.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software | 9.23.1 9.22.1.1 9.22.1.3 9.22.1.6 9.22.2 9.23.1.3 9.22.2.4 9.23.1.7 | No fixed version listed yet |
| Cisco Secure Firewall Threat Defense (FTD) Software | 7.6.0 7.7.0 7.6.1 7.6.2 7.7.10 7.7.11 7.6.2.1 7.7.10.1 | No fixed version listed yet |