ZeroHour

CVE-2026-20154

mass

Unauthenticated Remote DoS via Syslog 419002 Rate-Limiting Flaw in Cisco ASA/FTD

CVSS 3.1
8.6 high
EPSS
Published
()
Modified
AI analysis

Cisco Secure Firewall ASA and FTD Software improperly rate-limit syslog message 419002 (the message generated when the device detects a TCP SYN flood), a flaw tracked as CWE-835 in the system rate-limiting process. An unauthenticated, remote attacker triggers it simply by sending a flood of TCP SYN packets to the affected device. The result is high CPU utilization, performance degradation, and an availability-only denial-of-service condition (CVSS 8.6, Scope changed, Availability: High; confidentiality and integrity are not impacted). Any organization running Cisco ASA or FTD Software is potentially affected, particularly devices with internet-facing interfaces, although exact affected version ranges were not enumerated in the source data. As of this analysis there are no reports of in-the-wild exploitation, no public proof-of-concept, and the flaw is not on the CISA KEV list.

What to do: Consult the Cisco PSIRT advisory for CVE-2026-20154 and upgrade ASA/FTD to the fixed software releases it lists for your train. As interim mitigations, rate-limit or filter inbound TCP SYN traffic upstream (e.g., control-plane policing/upstream filtering), reduce unnecessary internet exposure of ASA/FTD interfaces, and monitor CPU usage ('show cpu usage') and syslog 419002 volume for signs of abuse. Inventory all internet-facing ASA/FTD deployments now, since no patch details are in the current data.

Affected
Cisco Secure Firewall Adaptive Security Appliance (ASA) SoftwareAffected releases not enumerated in provided data; see the Cisco PSIRT advisory for affected and fixed trains
Cisco Secure Firewall Threat Defense (FTD) SoftwareAffected releases not enumerated in provided data; see the Cisco PSIRT advisory for affected and fixed trains
Estimated exposure
masson the order of 10^5 devices (historical internet-wide scans have shown roughly 200,000+ exposed Cisco ASA/FTD firewalls) — Public internet scans have repeatedly counted on the order of 200,000 internet-exposed Cisco ASA/FTD appliances and the attack needs nothing more than the ability to send SYN packets to the device, though only the subset whose…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in the system rate-limiting process for syslog message 419002 of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause high CPU utilization on an affected device, resulting in a denial of service (DoS) condition. This vulnerability is due to improper rate limiting for syslog message 419002. An attacker could exploit this vulnerability by sending a flood of TCP synchronization (SYN) packets to an affected device. A successful exploit could allow the attacker to cause high CPU utilization, resulting in performance degradation.

Weakness
CWE-835
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.