CVE-2026-20250
largeUnauthenticated DTLS DoS (device reload) in Cisco Secure Firewall ASA/FTD 3100/4200
CVE-2026-20250 is a denial-of-service flaw in the Datagram TLS (DTLS) message handling of Cisco Secure Firewall ASA Software and Threat Defense (FTD) Software running on Cisco Secure Firewall 3100 and 4200 Series appliances. The bug stems from improper resource management (CWE-772) when processing certain DTLS messages, causing resources to not be released correctly. An unauthenticated, remote attacker can trigger it by sending a crafted stream of DTLS traffic to the device; a successful exploit causes the firewall to reload, taking down traffic inspection and any VPN services it terminates. Only 3100 and 4200 Series devices running ASA or FTD software are affected. There is currently no known exploitation, no CISA KEV listing, and no public proof-of-concept.
What to do: Inventory for Cisco Secure Firewall 3100/4200 Series appliances running ASA or FTD software, especially those terminating remote-access VPN with DTLS, and upgrade to the fixed release listed in Cisco's security advisory. As interim mitigation, restrict untrusted DTLS traffic from reaching the device (e.g., filter DTLS/UDP 443 at the perimeter or disable DTLS in VPN group policies if feasible). Monitor appliances for unexpected reloads, which may indicate exploitation attempts.
| Cisco Secure Firewall ASA Software (3100 Series) | — |
| Cisco Secure Firewall ASA Software (4200 Series) | — |
| Cisco Secure Firewall Threat Defense (FTD) Software (3100 Series) | — |
| Cisco Secure Firewall Threat Defense (FTD) Software (4200 Series) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability in Datagram TLS (DTLS) message handling of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software for Cisco Secure Firewall 3100 Series and 4200 Series devices could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper resource management when processing certain DTLS messages. An attacker could exploit this vulnerability by sending a crafted stream of DTLS traffic to an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.
- Weakness
- CWE-772
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.