ZeroHour

CVE-2026-20295

large

Unauthenticated Memory-Exhaustion DoS in Cisco Secure FMC/FTD sftunnel

CVSS 3.1
8.6 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-20295 is a memory-exhaustion flaw in sftunnel, the protocol Cisco Secure FMC (Firepower Management Center) and Secure FTD (Firepower Threat Defense) devices use to communicate with each other. Because memory resources are improperly managed during sftunnel TLS connection setup, an unauthenticated remote attacker can send crafted sftunnel TLS frames to exhaust the device's available memory. A successful attack does not disclose data or alter configurations, but can crash or stall the affected device, producing a denial-of-service condition; on FTD that can mean loss of firewall/IPS enforcement or management connectivity, and the scope-changed CVSS score (S:C) reflects that exploitation can impact other devices in the FMC-FTD deployment. Any organization running Cisco Secure FMC or Secure FTD software is potentially affected, particularly where sftunnel-capable interfaces are reachable by untrusted networks. As of this analysis there is no known public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been confirmed.

What to do: Monitor the Cisco PSIRT advisory for fixed releases and upgrade FMC and FTD deployments as soon as fixed software is available. Until then, restrict access to the sftunnel service (TCP 8305 by default) so it is reachable only from trusted management/peer networks and not from the internet, and watch for unexplained memory pressure, service restarts, or DoS symptoms on FMC and FTD devices.

Affected
Cisco Secure FMC Software (Firepower Management Center)
Cisco Secure FTD Software (Firepower Threat Defense)
Estimated exposure
largeTens of thousands of internet- and partner-reachable FMC/FTD systems (exact installed base unknown) — Cisco FTD/FMC are widely deployed enterprise firewall and central-management products, and public internet-wide scans routinely surface tens of thousands of exposed FTD/FMC management and sftunnel (TCP 8305) interfaces, though the total…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software and Cisco Secure FTD Software could allow an unauthenticated, remote attacker to exhaust the available memory of an affected device. This vulnerability is due to improper management of memory resources during sftunnel TLS connection setup. An attacker could exploit this vulnerability by sending crafted sftunnel TLS frames to an affected device during the connection setup. A successful exploit could allow the attacker to exhaust the available memory on the affected device, which could result in a DoS condition.

Weakness
CWE-789
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.