CVE-2026-20023
Cisco Adaptive Security Appliance (ASA) vulnerability analysis and mitigation

Overview

CVE-2026-20023 is a memory corruption vulnerability in the OSPF protocol implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software that allows an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. The vulnerability was discovered internally and first published on March 4, 2026, as part of Cisco's March 2026 Semiannual Firewall Security Advisory Bundled Publication. Affected products include Cisco ASA Software (versions 9.12.x through 9.23.x) and FTD Software (versions 6.4.0 through 7.7.10.1) when running the OSPF protocol. It carries a CVSS v3.1 base score of 6.1 (Medium) per the Cisco advisory, though NVD rates it 6.5 (Medium) (Cisco Advisory).

Technical details

The vulnerability is classified as CWE-787 (Out-of-bounds Write) and stems from improper memory handling when parsing OSPF protocol packets. Specifically, the affected code fails to properly validate OSPF packet data before writing to memory, resulting in an out-of-bounds write condition. An unauthenticated attacker on the same network segment (adjacent network) can exploit this by sending specially crafted OSPF packets to a vulnerable device; no authentication or user interaction is required. The vulnerability is tracked under Cisco Bug ID CSCwq73656 and is one of six OSPF-related CVEs (CVE-2026-20020 through CVE-2026-20025) addressed in the same advisory (Cisco Advisory).

Impact

Successful exploitation causes memory corruption on the affected Cisco ASA or FTD device, forcing it to reboot and resulting in a denial of service condition. The impact is limited to availability — there is no confidentiality or integrity impact — but a device reboot disrupts all firewall and network security operations for the duration of the outage. Because ASA and FTD devices typically serve as network perimeter security controls, their unavailability could expose downstream network segments to unfiltered traffic or disrupt VPN and routing services (Cisco Advisory).

Exploitation steps

  1. Reconnaissance: Identify Cisco ASA or FTD devices running OSPF within the target network segment using network scanning tools (e.g., Nmap with OSPF protocol detection) or by observing OSPF Hello packets on the local broadcast domain.
  2. Confirm adjacency: Verify that the attacker's system is on the same network segment or OSPF-reachable area as the target device, as the attack vector requires Layer 2 or OSPF adjacency.
  3. Craft malicious OSPF packets: Construct specially crafted OSPF packets designed to trigger the out-of-bounds write condition during packet parsing. This would require knowledge of the OSPF packet structure and the specific memory handling flaw.
  4. Transmit crafted packets: Send the malicious OSPF packets to the target Cisco ASA or FTD device. No authentication is required for this step.
  5. Trigger memory corruption: The vulnerable OSPF parsing code processes the malformed packet, causing an out-of-bounds write that corrupts device memory.
  6. Achieve DoS: The memory corruption causes the device to reboot, resulting in a denial of service condition and disruption of firewall and routing operations (Cisco Advisory).

Indicators of compromise

  • Network: Unexpected or malformed OSPF packets (e.g., invalid LSA types, oversized OSPF fields, or packets with anomalous length values) originating from an adjacent network segment; OSPF Hello packets from unknown or unauthorized neighbors.
  • Logs: Unexpected device reload or crash logs referencing OSPF processing; system logs showing memory fault or watchdog timeout events coinciding with OSPF traffic spikes.
  • Process/System: Unplanned device reboots on Cisco ASA or FTD appliances; post-reboot crash dumps referencing OSPF-related memory regions or stack traces.
  • Network Traffic: Sudden loss of OSPF adjacency followed by device unavailability; repeated OSPF neighbor state changes (FULL → DOWN) without a clear administrative cause.

Mitigation and workarounds

Cisco has released fixed software to address this vulnerability; there are no workarounds available. Organizations should use the Cisco Software Checker to identify their specific vulnerable release and the corresponding fixed version. As interim risk reduction measures, administrators should restrict OSPF adjacency to trusted, authenticated neighbors where possible, implement network segmentation to limit which devices can send OSPF traffic to the firewall, and enable OSPF authentication (MD5 or SHA) to raise the bar for exploitation. Cisco Secure Firewall Management Center (FMC) Software is not affected by this vulnerability (Cisco Advisory).

Community reactions

The vulnerability was discovered internally by Jason Crowder of Cisco's Advanced Security Initiatives Group (ASIG) and disclosed as part of Cisco's March 2026 semiannual bundled security advisory publication. The Center for Internet Security (CIS) issued an advisory noting multiple vulnerabilities in Cisco products. No significant independent researcher commentary or notable social media discussion has been identified beyond standard vulnerability tracking and aggregation sites (Cisco Advisory, CIS Advisory).

Additional resources


SourceThis report was generated using AI

Related Cisco Adaptive Security Appliance (ASA) vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-20012HIGH8.6
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:o:cisco:adaptive_security_appliance_software
NoYesMar 25, 2026
CVE-2026-20025MEDIUM6.8
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:o:cisco:adaptive_security_appliance_software
NoYesMar 04, 2026
CVE-2026-20023MEDIUM6.5
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:o:cisco:adaptive_security_appliance_software
NoYesMar 04, 2026
CVE-2026-20022MEDIUM6.5
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:o:cisco:adaptive_security_appliance_software
NoYesMar 04, 2026
CVE-2026-20024MEDIUM5.7
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:o:cisco:adaptive_security_appliance_software
NoYesMar 04, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management