CVE-2026-20025 Details
Description
A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an authenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a DoS condition. To exploit this vulnerability, the attacker must have the OSPF secret key. This vulnerability is due to insufficient input validation when processing OSPF link-state update (LSU) packets. An attacker could exploit this vulnerability by sending crafted OSPF LSU packets. A successful exploit could allow the attacker to corrupt the heap, causing the device to reload, resulting in a DoS condition.
A denial-of-service vulnerability has been identified in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software. This vulnerability allows an authenticated, adjacent attacker to cause an affected device to reload unexpectedly, leading to a DoS condition. The issue arises from insufficient input validation when processing OSPF link-state update packets. An attacker with knowledge of the OSPF secret key could exploit this vulnerability by sending crafted OSPF LSU packets, corrupting the heap and causing the device to reload.
Cisco has released software updates to address this vulnerability. Instructions for upgrading Cisco Secure FTD devices can be found in the Cisco Secure FMC upgrade guide. For Cisco Secure Firewall ASA, consult the Cisco Secure Firewall ASA Upgrade Guide. Customers can use the Cisco Software Checker tool to determine their exposure to this vulnerability and find the earliest fixed release.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 4, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ospf-ZH8PhbSW | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-190 | Integer Overflow or Wraparound | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cisco secure firewall threat defense | >= 6.4.0, < 7.0.9 >= 7.1.0, < 7.2.11 >= 7.3.0, < 7.4.3 >= 7.6.0, < 7.6.4 >= 7.7.0, < 7.7.11 |
CPE
Remediation
| |
| cisco adaptive security appliance software | >= 9.12.1, < 9.16.4.85 >= 9.17.1, < 9.18.4.66 >= 9.19.1, < 9.20.4 >= 9.22.1.1, < 9.22.2.4 >= 9.23.1, < 9.23.1.7 |
CPE
Remediation
| |
Change History
9 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 11, 2026 | CPE Deprecation Remap | [email protected] |
| Aug 11, 2026 | CPE Deprecation Remap | [email protected] |
| Aug 11, 2026 | CPE Deprecation Remap | [email protected] |
| Aug 11, 2026 | CPE Deprecation Remap | [email protected] |
| Aug 11, 2026 | CPE Deprecation Remap | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 5, 2026 | Initial Analysis | [email protected] |
| Mar 4, 2026 | New CVE Received | [email protected] |