
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20024 is a heap corruption vulnerability in the OSPF protocol implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software that allows an authenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. The attacker must possess the OSPF secret key to exploit this vulnerability. It was discovered internally by Jason Crowder of the Cisco Advanced Security Initiatives Group (ASIG) and publicly disclosed on March 4, 2026, as part of Cisco's March 2026 semiannual bundled security advisory publication. Affected products include Cisco Secure Firewall ASA Software (multiple versions across 9.12.x through 9.23.x) and Cisco Secure Firewall FTD Software (multiple versions across 6.4.x through 7.7.x). The vulnerability carries a CVSS v3.1 base score of 6.8 (Medium) per the Cisco advisory, or 5.7 (Medium) per NVD scoring (Cisco Advisory, Feedly).
The root cause is improper restriction of operations within the bounds of a memory buffer (CWE-119), specifically heap corruption occurring during OSPF packet parsing. When the OSPF service processes crafted packets from an attacker who possesses the OSPF authentication secret key, the parsing logic fails to properly validate input, leading to heap memory corruption. The attack vector is adjacent network (AV:A), requiring the attacker to be on the same network segment as the targeted device and to have authenticated access via the OSPF secret key — meaning the vulnerability cannot be exploited by unauthenticated or remote attackers. No public proof-of-concept code or technical write-ups beyond the vendor advisory are currently available (Cisco Advisory).
Successful exploitation causes heap corruption in the OSPF subsystem, forcing the affected Cisco Secure Firewall ASA or FTD device to reload unexpectedly and enter a denial of service condition. The impact is limited to availability — there is no confidentiality or integrity impact, and no evidence of code execution capability. In environments where the firewall is a critical network chokepoint, repeated exploitation could result in sustained network outages, disruption of security inspection, and potential exposure of protected network segments during device recovery (Cisco Advisory, Feedly).
Cisco has released fixed software versions and confirms there are no workarounds available for this vulnerability. For Cisco Secure Firewall ASA Software, upgrade to: 9.12.4.68 or later, 9.16.4.83 or later, 9.18.4.54 or later, 9.20.3.17 or later, or 9.22.1.7 or later. For Cisco Secure Firewall FTD Software, upgrade to: 6.4.0.19 or later, 7.0.8.2 or later, 7.2.9.1 or later, 7.4.2.5 or later, or 7.6.1 or later. As interim risk reduction measures, administrators should restrict network access to affected devices, rotate OSPF authentication keys, and disable OSPF if it is not operationally required (Cisco Advisory, Feedly).
The vulnerability was disclosed as part of Cisco's March 2026 semiannual bundled security advisory publication covering multiple OSPF-related vulnerabilities (CVE-2026-20020 through CVE-2026-20025) in Cisco Secure Firewall products. The Center for Internet Security (CIS) issued an advisory noting multiple vulnerabilities in Cisco products. No significant independent researcher commentary, social media discussion, or media coverage specific to CVE-2026-20024 has been observed, consistent with its medium severity rating and the authentication prerequisite limiting its exploitability (Cisco Advisory, CIS Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."