
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20025 is a denial-of-service (DoS) vulnerability in the OSPF protocol implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software. An authenticated, adjacent attacker who possesses the OSPF secret key can send crafted OSPF link-state update (LSU) packets to corrupt the heap and cause the affected device to reload unexpectedly. The vulnerability was disclosed on March 4, 2026, as part of Cisco's March 2026 Semiannual Firewall Security Advisory Bundled Publication, and was discovered internally by Jason Crowder of the Cisco Advanced Security Initiatives Group (ASIG). Affected ASA versions include 9.12.1–9.16.4.84, 9.17.1–9.18.4.65, 9.19.1–9.20.3, 9.22.1.1–9.22.2.3, and 9.23.1–9.23.1.6; affected FTD versions include 6.4.0–7.0.8, 7.1.0–7.2.10, 7.3.0–7.4.2, 7.6.0–7.6.3, and 7.7.0–7.7.10. It carries a CVSS v3.1 base score of 6.8 (Medium) (Cisco Advisory).
The root cause is classified as CWE-190 (Integer Overflow or Wraparound), arising from insufficient input validation when processing OSPF LSU packets. When a crafted LSU packet is received, an integer overflow condition leads to heap corruption, ultimately causing the device to reload. Exploitation requires the attacker to be adjacent (layer-2 network segment) and authenticated — specifically, they must possess the OSPF shared secret key configured on the device. No public proof-of-concept or technical write-up beyond the vendor advisory is currently available. The vulnerability is tracked under Cisco Bug ID CSCwn69078 and is one of six related OSPF vulnerabilities addressed in the same advisory (Cisco Advisory).
Successful exploitation results in a heap corruption condition that forces the affected Cisco ASA or FTD device to reload, causing a denial-of-service condition. There is no confidentiality or integrity impact — the vulnerability is purely an availability concern. Because the affected devices are network security appliances (firewalls), a successful DoS attack could disrupt network traffic inspection, VPN termination, and access control enforcement for all traffic passing through the device, potentially enabling lateral movement or data exfiltration through the resulting security gap (Cisco Advisory).
Cisco has released fixed software versions and confirms there are no workarounds available for this vulnerability. Organizations should upgrade to the following fixed releases based on their current version branch — ASA Software: 9.16.4.85, 9.18.4.66, 9.20.4, 9.22.2.4, or 9.23.1.7; FTD Software: 7.0.9, 7.2.11, 7.4.3, 7.6.4, or 7.7.11. As interim risk-reduction measures, administrators should restrict OSPF neighbor relationships to trusted devices using OSPF neighbor authentication with strong, unique keys, and apply interface-level access controls to limit OSPF traffic to known, authorized sources (Cisco Advisory).
The Center for Internet Security (CIS) issued an advisory noting multiple vulnerabilities in Cisco products addressed in the March 2026 bundled publication (CIS Advisory). Cisco PSIRT confirmed the vulnerability was discovered internally and has not observed any public exploitation or announcements (Cisco Advisory). Community reaction has been limited given the Medium severity rating and the authentication prerequisite, with no notable researcher commentary or significant social media discussion identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."