rootpwn

Vulnerabilities

Cisco ASA/FTD DTLS DoS Vulnerability (CVE‑2026‑20250) – Immediate Patch Required

Cisco’s Adaptive Security Appliance (ASA) and Threat Defense (FTD) software for the 3100 and 4200 series can be forced into a denial‑of‑service state by an unauthenticated attacker sending crafted DTLS traffic. The flaw stems from improper resource handling during DTLS message processing, causing a device reload. Cisco has issued patches and workarounds; applying the update is essential to keep firewalls online.

What’s at stake

An unauthenticated remote attacker can trigger a device reboot on ASA and FTD firewalls by flooding them with malicious DTLS packets. The resulting reboot leaves the firewall offline, disrupting network traffic and potentially exposing the organization to further attacks.

How the flaw works

The vulnerability lies in DTLS message handling where resource limits are not correctly enforced. When the firewall receives a specially crafted stream of DTLS packets, it exhausts internal buffers, forces a reload, and drops connectivity.

Affected devices

  • ASA Software on Cisco Secure Firewall 3100 Series
  • ASA Software on Cisco Secure Firewall 4200 Series
  • FTD Software on Cisco Secure Firewall 3100 Series
  • FTD Software on Cisco Secure Firewall 4200 Series

Mitigation steps

  • Install the latest Cisco firmware updates that address CVE‑2026‑20250.
  • If immediate patching isn’t possible, apply the documented workarounds to mitigate the risk.
  • Block or rate‑limit DTLS traffic at the network perimeter until a patch is applied.

Patch status

Cisco has released software updates for all affected ASA and FTD models. The advisory recommends prompt deployment of these fixes to eliminate the DoS vector. Keep your devices updated and monitor Cisco’s security portal for any additional guidance.

Cisco DTLS DoS CVE-2026-20250 Firewall Patch ASA FTD

← All news