CVE-2026-20154
massUnauthenticated Remote DoS via Syslog 419002 Rate-Limiting Flaw in Cisco ASA/FTD
Cisco Secure Firewall ASA and FTD Software improperly rate-limit syslog message 419002 (the message generated when the device detects a TCP SYN flood), a flaw tracked as CWE-835 in the system rate-limiting process. An unauthenticated, remote attacker triggers it simply by sending a flood of TCP SYN packets to the affected device. The result is high CPU utilization, performance degradation, and an availability-only denial-of-service condition (CVSS 8.6, Scope changed, Availability: High; confidentiality and integrity are not impacted). Any organization running Cisco ASA or FTD Software is potentially affected, particularly devices with internet-facing interfaces, although exact affected version ranges were not enumerated in the source data. As of this analysis there are no reports of in-the-wild exploitation, no public proof-of-concept, and the flaw is not on the CISA KEV list.
What to do: Consult the Cisco PSIRT advisory for CVE-2026-20154 and upgrade ASA/FTD to the fixed software releases it lists for your train. As interim mitigations, rate-limit or filter inbound TCP SYN traffic upstream (e.g., control-plane policing/upstream filtering), reduce unnecessary internet exposure of ASA/FTD interfaces, and monitor CPU usage ('show cpu usage') and syslog 419002 volume for signs of abuse. Inventory all internet-facing ASA/FTD deployments now, since no patch details are in the current data.
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software | Affected releases not enumerated in provided data; see the Cisco PSIRT advisory for affected and fixed trains |
| Cisco Secure Firewall Threat Defense (FTD) Software | Affected releases not enumerated in provided data; see the Cisco PSIRT advisory for affected and fixed trains |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability in the system rate-limiting process for syslog message 419002 of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause high CPU utilization on an affected device, resulting in a denial of service (DoS) condition. This vulnerability is due to improper rate limiting for syslog message 419002. An attacker could exploit this vulnerability by sending a flood of TCP synchronization (SYN) packets to an affected device. A successful exploit could allow the attacker to cause high CPU utilization, resulting in performance degradation.
- Weakness
- CWE-835
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.