CVE-2026-20025
Cisco Adaptive Security Appliance (ASA) vulnerability analysis and mitigation

Overview

CVE-2026-20025 is a denial-of-service (DoS) vulnerability in the OSPF protocol implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software. An authenticated, adjacent attacker who possesses the OSPF secret key can send crafted OSPF link-state update (LSU) packets to corrupt the heap and cause the affected device to reload unexpectedly. The vulnerability was disclosed on March 4, 2026, as part of Cisco's March 2026 Semiannual Firewall Security Advisory Bundled Publication, and was discovered internally by Jason Crowder of the Cisco Advanced Security Initiatives Group (ASIG). Affected ASA versions include 9.12.1–9.16.4.84, 9.17.1–9.18.4.65, 9.19.1–9.20.3, 9.22.1.1–9.22.2.3, and 9.23.1–9.23.1.6; affected FTD versions include 6.4.0–7.0.8, 7.1.0–7.2.10, 7.3.0–7.4.2, 7.6.0–7.6.3, and 7.7.0–7.7.10. It carries a CVSS v3.1 base score of 6.8 (Medium) (Cisco Advisory).

Technical details

The root cause is classified as CWE-190 (Integer Overflow or Wraparound), arising from insufficient input validation when processing OSPF LSU packets. When a crafted LSU packet is received, an integer overflow condition leads to heap corruption, ultimately causing the device to reload. Exploitation requires the attacker to be adjacent (layer-2 network segment) and authenticated — specifically, they must possess the OSPF shared secret key configured on the device. No public proof-of-concept or technical write-up beyond the vendor advisory is currently available. The vulnerability is tracked under Cisco Bug ID CSCwn69078 and is one of six related OSPF vulnerabilities addressed in the same advisory (Cisco Advisory).

Impact

Successful exploitation results in a heap corruption condition that forces the affected Cisco ASA or FTD device to reload, causing a denial-of-service condition. There is no confidentiality or integrity impact — the vulnerability is purely an availability concern. Because the affected devices are network security appliances (firewalls), a successful DoS attack could disrupt network traffic inspection, VPN termination, and access control enforcement for all traffic passing through the device, potentially enabling lateral movement or data exfiltration through the resulting security gap (Cisco Advisory).

Exploitation steps

  1. Reconnaissance: Identify target Cisco ASA or FTD devices running OSPF on an adjacent network segment. Use network scanning tools (e.g., Nmap with OSPF-aware scripts) or passive traffic analysis to detect OSPF Hello packets, which reveal participating routers and their OSPF area configurations.
  2. Obtain OSPF Secret Key: Acquire the OSPF MD5 or SHA authentication key through credential theft, insider access, configuration file exposure, or compromise of another OSPF-speaking device on the same segment.
  3. Craft Malicious LSU Packet: Construct a specially crafted OSPF Link-State Update (LSU) packet that triggers an integer overflow in the ASA/FTD OSPF parsing code. The packet must be authenticated using the obtained OSPF secret key to pass authentication checks.
  4. Transmit Packet: Send the crafted LSU packet from a host on the same layer-2 network segment as the target firewall's OSPF-enabled interface, as OSPF operates at the adjacent network level (multicast to 224.0.0.5 or 224.0.0.6).
  5. Trigger DoS: The malformed LSU causes an integer overflow leading to heap corruption in the OSPF processing code, forcing the device to reload and resulting in a denial-of-service condition (Cisco Advisory).

Indicators of compromise

  • Network: Unexpected or malformed OSPF LSU packets on monitored segments, particularly those with unusual LSA lengths or type fields; OSPF packets authenticated with a known key originating from an unexpected source MAC/IP address.
  • Logs: Repeated device reload events logged in syslog with OSPF-related crash signatures; ASA/FTD system logs showing unexpected process restarts or watchdog timeouts correlated with OSPF activity.
  • Process/System: Unexpected device reloads or crashinfo files generated on the ASA/FTD; post-reload crashinfo referencing OSPF LSU processing or heap corruption in the OSPF daemon.
  • Configuration: Review of OSPF neighbor tables for unexpected adjacencies formed with unknown devices on OSPF-enabled interfaces.

Mitigation and workarounds

Cisco has released fixed software versions and confirms there are no workarounds available for this vulnerability. Organizations should upgrade to the following fixed releases based on their current version branch — ASA Software: 9.16.4.85, 9.18.4.66, 9.20.4, 9.22.2.4, or 9.23.1.7; FTD Software: 7.0.9, 7.2.11, 7.4.3, 7.6.4, or 7.7.11. As interim risk-reduction measures, administrators should restrict OSPF neighbor relationships to trusted devices using OSPF neighbor authentication with strong, unique keys, and apply interface-level access controls to limit OSPF traffic to known, authorized sources (Cisco Advisory).

Community reactions

The Center for Internet Security (CIS) issued an advisory noting multiple vulnerabilities in Cisco products addressed in the March 2026 bundled publication (CIS Advisory). Cisco PSIRT confirmed the vulnerability was discovered internally and has not observed any public exploitation or announcements (Cisco Advisory). Community reaction has been limited given the Medium severity rating and the authentication prerequisite, with no notable researcher commentary or significant social media discussion identified.

Additional resources


SourceThis report was generated using AI

Related Cisco Adaptive Security Appliance (ASA) vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-20012HIGH8.6
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:o:cisco:adaptive_security_appliance_software
NoYesMar 25, 2026
CVE-2026-20025MEDIUM6.8
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:o:cisco:adaptive_security_appliance_software
NoYesMar 04, 2026
CVE-2026-20023MEDIUM6.5
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:o:cisco:adaptive_security_appliance_software
NoYesMar 04, 2026
CVE-2026-20022MEDIUM6.5
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:o:cisco:adaptive_security_appliance_software
NoYesMar 04, 2026
CVE-2026-20024MEDIUM5.7
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:o:cisco:adaptive_security_appliance_software
NoYesMar 04, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management