CVE-2026-20135
largeUnauthenticated DoS (device reload) in Cisco Secure Firewall FTD via crafted TLS 1.3 packets
CVE-2026-20135 is a double-free (improper buffer management, CWE-415) flaw in the TLS 1.3 implementation of Cisco Secure Firewall Threat Defense (FTD) Software. An unauthenticated, remote attacker can trigger it by sending a crafted TLS 1.3 packet to any TLS 1.3-enabled listening socket, covering both data traffic and user-management traffic, and exploitation can succeed before or after connection authentication. A successful attack crashes the LINA process, forcing the device to reload and causing a denial of service; confidentiality and integrity are not impacted. Any organization running FTD with TLS 1.3 enabled on exposed listeners is affected. No exploitation in the wild or public proof-of-concept is currently known, and the flaw is not in CISA's KEV catalog.
What to do: Consult the Cisco security advisory (assigned by [email protected]) for fixed FTD releases and upgrade as soon as fixed software is available for your release train. As interim mitigation, disable TLS 1.3 on listening sockets where possible or restrict access to TLS 1.3-enabled interfaces (especially user-management traffic) to trusted networks only. Check devices for unexpected reloads or LINA process crashes, which may indicate exploitation attempts.
| Cisco Secure Firewall Threat Defense (FTD) Software | Version ranges not specified in the available data; affected are FTD deployments with TLS 1.3-enabled listening sockets (both data-plane and user-management tra |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability in the TLS 1.3 implementation in Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to improper buffer management during the TLS 1.3 connection. An attacker could exploit this vulnerability by sending a crafted TLS 1.3 packet to an affected system through a TLS 1.3-enabled listening socket. A successful exploit could allow the attacker to cause the LINA process to crash, which would cause the device to reload. The reload can happen before or after authentication of the connection.Note: TLS 1.3 connections include both data traffic and user-management traffic.
- Weakness
- CWE-415
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.