
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20020 is a Denial of Service (DoS) vulnerability in the OSPF protocol implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software. An unauthenticated, adjacent attacker can exploit this flaw to cause an affected device to reload unexpectedly; if OSPF authentication is enabled, the attacker must know the OSPF secret key. The vulnerability was disclosed on March 4, 2026, as part of Cisco's March 2026 Semiannual Cisco Secure Firewall Security Advisory Bundled Publication. Affected ASA versions span the 9.12.x through 9.23.x trains, and affected FTD versions span 6.4.0 through 7.7.x. It carries a CVSS v3.1 base score of 6.8 (Medium) (Cisco Advisory).
The root cause is insufficient input validation when processing OSPF update packets (CWE-20), which leads to a buffer overflow condition. An attacker on the same network segment as the OSPF-enabled interface sends crafted OSPF update packets; the device fails to properly validate the packet contents, triggering a buffer overflow that causes the device to reload. The attack vector is adjacent network (Layer 2 or same broadcast domain), requires low privileges (or knowledge of the OSPF secret key if authentication is configured), and no user interaction. The vulnerability was discovered internally by Jason Crowder of the Cisco Advanced Security Initiatives Group (ASIG) and is tracked as Bug ID CSCwn69076 (Cisco Advisory).
Successful exploitation results in an unexpected device reload, causing a Denial of Service condition on the affected Cisco ASA or FTD firewall. There is no confidentiality or integrity impact — the vulnerability is purely an availability issue. Because ASA and FTD devices typically serve as network perimeter security controls, repeated exploitation could disrupt network connectivity, disable firewall inspection, and potentially expose downstream network segments to unfiltered traffic during the outage period (Cisco Advisory).
%ASA-1-105004: (Primary) Failover message block alloc failed or similar crash-related messages); OSPF process crash or restart events in system logs.Cisco has released fixed software to address this vulnerability; there are no workarounds available. Administrators should use the Cisco Software Checker tool to identify the appropriate fixed release for their deployment. Key remediation steps include:
The vulnerability was part of Cisco's March 2026 Semiannual Cisco Secure Firewall ASA, Secure FMC, and Secure FTD Software Security Advisory Bundled Publication, which covered multiple OSPF-related CVEs (CVE-2026-20020 through CVE-2026-20025). The Center for Internet Security (CIS) issued an advisory noting multiple vulnerabilities in Cisco products that could allow for remote code execution and DoS conditions. Community aggregators including VulDB, CVEFeed, and threat intelligence platforms tracked the disclosure shortly after publication. No significant independent researcher commentary or social media controversy has been identified for this specific CVE (Cisco Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."