ZeroHour

CVE-2026-20222

large

Unauthenticated Adjacent Memory-Leak DoS in Cisco Secure Firewall ASA/FTD EIGRP

CVSS 3.1
7.4 high
EPSS
Published
()
Modified
AI analysis

Cisco Secure Firewall ASA and FTD software contain a memory leak (CWE-401) in the handling of EIGRP update messages, caused by improper resource management. An unauthenticated attacker positioned adjacent to the device (on a segment where EIGRP is configured) can send crafted EIGRP updates at a high rate, exhausting memory until the firewall reloads unexpectedly. A successful attack yields only a denial of service (CVSS availability impact, no confidentiality or integrity loss), but repeated exploitation could keep the firewall crashing, disrupting all traffic it inspects. Only deployments of Cisco ASA or FTD software with EIGRP enabled are affected, and the attacker must be able to reach an EIGRP-enabled interface. Exploitation status: no reports of in-the-wild abuse, no public proof-of-concept, and the flaw is not in CISA KEV.

What to do: Upgrade ASA and FTD to the fixed releases listed in the Cisco security advisory. As interim mitigation, enable EIGRP neighbor authentication and/or interface access lists restricting which hosts can send EIGRP packets to the firewall, and disable EIGRP where it is not required. Check whether EIGRP is configured on any interface and monitor device memory utilization for unexplained growth.

Affected
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
Cisco Secure Firewall Threat Defense (FTD) Software
Estimated exposure
largetens of thousands of ASA/FTD deployments plausibly affected (subset of Cisco's multi-million-unit firewall installed base that runs EIGRP) — Cisco ASA/FTD firewalls have a very large installed base (public internet scans routinely show on the order of 100k+ exposed units), but exploitation requires adjacency and EIGRP routing enabled on the device, so only the minority of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in the EIGRP implementation in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to improper resource management when handling EIGRP update messages. An attacker could exploit this vulnerability by sending crafted EIGRP updates at a high rate to an affected device. A successful exploit could allow the attacker to trigger a memory leak that will eventually cause the affected device to reload unexpectedly.

Weakness
CWE-401
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.