rootpwn

medium · CVSS v3 5.8

CVE-2026-20120

A logic flaw in Cisco Secure Firewall ASA and FTD’s ACL Object Group Search (OGS) can let an unauthenticated remote attacker bypass configur

Overview

A logic flaw in Cisco Secure Firewall ASA and FTD’s ACL Object Group Search (OGS) can let an unauthenticated remote attacker bypass configured access controls. The flaw allows traffic that should be blocked to pass through the firewall, potentially exposing protected network resources.

Description

A vulnerability in the access control list (ACL) Object Group Search (OGS) implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured access controls. This vulnerability is due to a logic error in populating group access control policies (ACPs) with OGS configured. An attacker could exploit this vulnerability by sending traffic that should be blocked through the device. A successful exploit could allow the attacker to bypass access controls and reach devices in protected networks.

Impact

Unauthorized traffic can reach protected networks, compromising confidentiality and integrity of data. Attackers may exfiltrate sensitive information or introduce malicious payloads, potentially affecting availability if the firewall is overwhelmed or misconfigured.

Remediation

['Verify the current ASA/FTD firmware version and apply the latest Cisco security patch that addresses CVE-2026-20120.', 'Disable or reconfigure Object Group Search (OGS) if it is not required, and ensure ACLs are explicitly defined without relying on OGS for policy enforcement.', 'Perform a post‑patch validation test to confirm that ACLs are correctly enforced and that blocked traffic is no longer allowed.', 'Enable logging for ACL violations and monitor logs for anomalous traffic patterns.', 'If immediate patching is not possible, isolate the affected firewall from critical internal networks until remediation is completed.']

Risk context

{'severity': 'medium', 'cvss_v3': 5.8, 'epss': None, 'advisory': 'Cisco Security Advisory for ASA/FTD – CVE-2026-20120'}

Affected products

  • Cisco Secure Firewall Adaptive Security Appliance (ASA)
  • Cisco Secure Firewall Threat Defense (FTD)
  • Cisco Secure Firewall

Scores

Severity
medium
CVSS v2
5
CVSS v3
5.8
CVSS v4
EPSS

access-control-bypass Cisco-ASA Cisco-FTD network-security ACL remote-unauthenticated medium

← All CVEs