CVE-2026-20024
Cisco Adaptive Security Appliance (ASA) vulnerability analysis and mitigation

Overview

CVE-2026-20024 is a heap corruption vulnerability in the OSPF protocol implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software that allows an authenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. The attacker must possess the OSPF secret key to exploit this vulnerability. It was discovered internally by Jason Crowder of the Cisco Advanced Security Initiatives Group (ASIG) and publicly disclosed on March 4, 2026, as part of Cisco's March 2026 semiannual bundled security advisory publication. Affected products include Cisco Secure Firewall ASA Software (multiple versions across 9.12.x through 9.23.x) and Cisco Secure Firewall FTD Software (multiple versions across 6.4.x through 7.7.x). The vulnerability carries a CVSS v3.1 base score of 6.8 (Medium) per the Cisco advisory, or 5.7 (Medium) per NVD scoring (Cisco Advisory, Feedly).

Technical details

The root cause is improper restriction of operations within the bounds of a memory buffer (CWE-119), specifically heap corruption occurring during OSPF packet parsing. When the OSPF service processes crafted packets from an attacker who possesses the OSPF authentication secret key, the parsing logic fails to properly validate input, leading to heap memory corruption. The attack vector is adjacent network (AV:A), requiring the attacker to be on the same network segment as the targeted device and to have authenticated access via the OSPF secret key — meaning the vulnerability cannot be exploited by unauthenticated or remote attackers. No public proof-of-concept code or technical write-ups beyond the vendor advisory are currently available (Cisco Advisory).

Impact

Successful exploitation causes heap corruption in the OSPF subsystem, forcing the affected Cisco Secure Firewall ASA or FTD device to reload unexpectedly and enter a denial of service condition. The impact is limited to availability — there is no confidentiality or integrity impact, and no evidence of code execution capability. In environments where the firewall is a critical network chokepoint, repeated exploitation could result in sustained network outages, disruption of security inspection, and potential exposure of protected network segments during device recovery (Cisco Advisory, Feedly).

Exploitation steps

  1. Reconnaissance: Identify Cisco Secure Firewall ASA or FTD devices running OSPF on an adjacent network segment using network scanning tools (e.g., Nmap with OSPF protocol detection or passive traffic analysis).
  2. Obtain OSPF secret key: Acquire the OSPF authentication secret key through insider access, credential theft, configuration file exposure, or other means — this is a hard prerequisite for exploitation.
  3. Craft malicious OSPF packets: Construct specially crafted OSPF packets designed to trigger heap corruption during the parsing phase of the OSPF service on the target device.
  4. Transmit crafted packets: Send the crafted OSPF packets to the target device from an adjacent network position, authenticating with the known OSPF secret key to pass authentication checks.
  5. Trigger DoS: The malformed packets cause heap corruption in the OSPF parsing routine, forcing the device to reload unexpectedly and resulting in a denial of service condition (Cisco Advisory).

Indicators of compromise

  • Network: Unexpected or malformed OSPF packets on the network segment adjacent to the firewall; OSPF packets with anomalous structure or length fields from unexpected sources.
  • Logs: Cisco ASA or FTD system logs showing unexpected device reload events; crash dump or core files generated around the time of the reload; OSPF process crash messages in system logs.
  • Process/System: Unexpected device reloads or reboots without administrative action; OSPF adjacency drops followed by device restart events visible in syslog or SNMP traps.
  • Configuration: Review of OSPF authentication configuration to identify whether the secret key may have been compromised or shared with unauthorized parties (Cisco Advisory).

Mitigation and workarounds

Cisco has released fixed software versions and confirms there are no workarounds available for this vulnerability. For Cisco Secure Firewall ASA Software, upgrade to: 9.12.4.68 or later, 9.16.4.83 or later, 9.18.4.54 or later, 9.20.3.17 or later, or 9.22.1.7 or later. For Cisco Secure Firewall FTD Software, upgrade to: 6.4.0.19 or later, 7.0.8.2 or later, 7.2.9.1 or later, 7.4.2.5 or later, or 7.6.1 or later. As interim risk reduction measures, administrators should restrict network access to affected devices, rotate OSPF authentication keys, and disable OSPF if it is not operationally required (Cisco Advisory, Feedly).

Community reactions

The vulnerability was disclosed as part of Cisco's March 2026 semiannual bundled security advisory publication covering multiple OSPF-related vulnerabilities (CVE-2026-20020 through CVE-2026-20025) in Cisco Secure Firewall products. The Center for Internet Security (CIS) issued an advisory noting multiple vulnerabilities in Cisco products. No significant independent researcher commentary, social media discussion, or media coverage specific to CVE-2026-20024 has been observed, consistent with its medium severity rating and the authentication prerequisite limiting its exploitability (Cisco Advisory, CIS Advisory).

Additional resources


SourceThis report was generated using AI

Related Cisco Adaptive Security Appliance (ASA) vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-20012HIGH8.6
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:o:cisco:adaptive_security_appliance_software
NoYesMar 25, 2026
CVE-2026-20025MEDIUM6.8
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:o:cisco:adaptive_security_appliance_software
NoYesMar 04, 2026
CVE-2026-20023MEDIUM6.5
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:o:cisco:adaptive_security_appliance_software
NoYesMar 04, 2026
CVE-2026-20022MEDIUM6.5
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:o:cisco:adaptive_security_appliance_software
NoYesMar 04, 2026
CVE-2026-20024MEDIUM5.7
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:o:cisco:adaptive_security_appliance_software
NoYesMar 04, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management