
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20022 is a denial-of-service (DoS) vulnerability in the OSPF protocol implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software. The flaw allows an unauthenticated, adjacent attacker to cause an affected device to reload unexpectedly when OSPF canonicalization debug is enabled via the command debug ip ospf canon. It was discovered internally by Jason Crowder of the Cisco Advanced Security Initiatives Group (ASIG) and publicly disclosed on March 4, 2026, as part of Cisco's March 2026 Semiannual Firewall Security Advisory Bundled Publication. Affected products include Cisco ASA Software (multiple versions from 9.12.x through 9.23.x) and Cisco FTD Software (versions from 6.4.0.x through 7.7.x). The CVSS v3.1 base score is 6.1 (Medium), with an adjacent network attack vector and no authentication required (Cisco Advisory).
The vulnerability is classified as CWE-823 (Use of Out-of-Range Pointer Offset) and stems from insufficient input validation when processing OSPF Link-State Update (LSU) packets. When the OSPF canonicalization debug mode is active (debug ip ospf canon), a crafted unauthenticated OSPF packet can cause the software to write to memory outside the bounds of the packet data buffer, triggering a device reload. The attack requires adjacency to the target network segment (Layer 2 proximity or routing adjacency) but does not require authentication or prior privileges. This vulnerability is tracked under Cisco Bug IDs CSCwo71552 and CSCwn69081, and is one of six related OSPF vulnerabilities addressed in the same advisory (Cisco Advisory).
Successful exploitation results in an unexpected device reload, causing a denial-of-service condition on the affected Cisco ASA or FTD appliance. There is no confidentiality or integrity impact — the vulnerability exclusively affects availability. Because these devices typically serve as network security perimeters or gateways, a forced reload could disrupt network connectivity, interrupt VPN sessions, and temporarily disable firewall inspection for all traffic passing through the affected device. The impact is limited to the targeted device and does not directly enable lateral movement or data exfiltration (Cisco Advisory).
debug ip ospf canon). This is a non-default, operator-enabled debug mode; exploitation is only possible when this mode is active.debug ip ospf canon is active; repeated reload events correlated with OSPF traffic spikes from a specific adjacent host.Cisco has released fixed software versions addressing CVE-2026-20022. Administrators should use the Cisco Software Checker tool to identify the appropriate fixed release for their specific ASA or FTD version. The primary mitigation is to upgrade to a patched software release. As an immediate operational measure, disabling the OSPF canonicalization debug mode (no debug ip ospf canon) eliminates the precondition required for exploitation, effectively removing the attack surface until a patch can be applied. Cisco has confirmed there are no configuration-based workarounds that fully address the vulnerability. Cisco FMC Software is not affected (Cisco Advisory).
The vulnerability was disclosed as part of Cisco's March 2026 Semiannual Firewall Security Advisory Bundled Publication, which covered six related OSPF vulnerabilities across ASA and FTD products. The Center for Internet Security (CIS) issued an advisory noting that multiple vulnerabilities in Cisco products could allow for remote code execution and DoS conditions. Community and media attention has been moderate, consistent with the Medium severity rating and the non-default precondition (debug mode) required for exploitation. No notable independent researcher commentary or significant social media discussion specific to CVE-2026-20022 has been identified (CIS Advisory, Cisco Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."