ZeroHour

CVE-2026-20135

large

Unauthenticated DoS (device reload) in Cisco Secure Firewall FTD via crafted TLS 1.3 packets

CVSS 3.1
8.6 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-20135 is a double-free (improper buffer management, CWE-415) flaw in the TLS 1.3 implementation of Cisco Secure Firewall Threat Defense (FTD) Software. An unauthenticated, remote attacker can trigger it by sending a crafted TLS 1.3 packet to any TLS 1.3-enabled listening socket, covering both data traffic and user-management traffic, and exploitation can succeed before or after connection authentication. A successful attack crashes the LINA process, forcing the device to reload and causing a denial of service; confidentiality and integrity are not impacted. Any organization running FTD with TLS 1.3 enabled on exposed listeners is affected. No exploitation in the wild or public proof-of-concept is currently known, and the flaw is not in CISA's KEV catalog.

What to do: Consult the Cisco security advisory (assigned by [email protected]) for fixed FTD releases and upgrade as soon as fixed software is available for your release train. As interim mitigation, disable TLS 1.3 on listening sockets where possible or restrict access to TLS 1.3-enabled interfaces (especially user-management traffic) to trusted networks only. Check devices for unexpected reloads or LINA process crashes, which may indicate exploitation attempts.

Affected
Cisco Secure Firewall Threat Defense (FTD) SoftwareVersion ranges not specified in the available data; affected are FTD deployments with TLS 1.3-enabled listening sockets (both data-plane and user-management tra
Estimated exposure
largeOrder of 100,000+ FTD deployments potentially in scope, with a smaller internet-exposed subset (unknown exactly) — Cisco Secure Firewall (formerly Firepower/ASA-based FTD) is one of the most widely deployed enterprise NGFW lines with a vendor-stated installed base in the hundreds of thousands to over a million units, though only devices with TLS…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in the TLS 1.3 implementation in Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to improper buffer management during the TLS 1.3 connection. An attacker could exploit this vulnerability by sending a crafted TLS 1.3 packet to an affected system through a TLS 1.3-enabled listening socket. A successful exploit could allow the attacker to cause the LINA process to crash, which would cause the device to reload. The reload can happen before or after authentication of the connection.Note: TLS 1.3 connections include both data traffic and user-management traffic.

Weakness
CWE-415
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.