ZeroHour

CVE-2026-20250

large

Unauthenticated DTLS DoS (device reload) in Cisco Secure Firewall ASA/FTD 3100/4200

CVSS 3.1
8.6 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-20250 is a denial-of-service flaw in the Datagram TLS (DTLS) message handling of Cisco Secure Firewall ASA Software and Threat Defense (FTD) Software running on Cisco Secure Firewall 3100 and 4200 Series appliances. The bug stems from improper resource management (CWE-772) when processing certain DTLS messages, causing resources to not be released correctly. An unauthenticated, remote attacker can trigger it by sending a crafted stream of DTLS traffic to the device; a successful exploit causes the firewall to reload, taking down traffic inspection and any VPN services it terminates. Only 3100 and 4200 Series devices running ASA or FTD software are affected. There is currently no known exploitation, no CISA KEV listing, and no public proof-of-concept.

What to do: Inventory for Cisco Secure Firewall 3100/4200 Series appliances running ASA or FTD software, especially those terminating remote-access VPN with DTLS, and upgrade to the fixed release listed in Cisco's security advisory. As interim mitigation, restrict untrusted DTLS traffic from reaching the device (e.g., filter DTLS/UDP 443 at the perimeter or disable DTLS in VPN group policies if feasible). Monitor appliances for unexpected reloads, which may indicate exploitation attempts.

Affected
Cisco Secure Firewall ASA Software (3100 Series)
Cisco Secure Firewall ASA Software (4200 Series)
Cisco Secure Firewall Threat Defense (FTD) Software (3100 Series)
Cisco Secure Firewall Threat Defense (FTD) Software (4200 Series)
Estimated exposure
largelikely tens of thousands of deployed devices (3100/4200 Series appliances with VPN/DTLS enabled) — The 3100 and 4200 Series are Cisco's current-generation mid-range firewall appliances widely deployed at enterprise edges, and public internet scans historically show tens of thousands of exposed Cisco ASA/FTD endpoints, a large share of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in Datagram TLS (DTLS) message handling of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software for Cisco Secure Firewall 3100 Series and 4200 Series devices could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper resource management when processing certain DTLS messages. An attacker could exploit this vulnerability by sending a crafted stream of DTLS traffic to an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.

Weakness
CWE-772
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.