CVE-2026-20250
CVE-2026-20250: 1 tracked advisory record across Cisco. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Cisco
1 advisory- Advisory severityHigh8.6
High [CVE-2026-20250] Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software for Secure Firewall 3100 and 4200 Series DTLS Denial of Service Vulnerability
cisco-sa-asaftd-dtls-dos-Kp57HkyOSource published Source updated
A vulnerability in Datagram TLS (DTLS) message handling of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software for Cisco Secure Firewall 3100 Series and 4200 Series devices could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper resource management when processing certain DTLS messages. An attacker could exploit this vulnerability by sending a crafted stream of DTLS traffic to an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition. Cisco has released software updates that address this vulnerability. There are workarounds that address this vulnerability.…
- Affected products in this advisory
- Secure Firewall Adaptive Security Appliance (ASA) Software
- Secure Firewall 3100 Series
- Secure Firewall 4200 Series
- Secure Firewall Threat Defense (FTD) Software
- Source-reported affected versions
- Scope: This vulnerability affects Cisco Secure Firewall 3100 Series and 4200 Series devices if they are running a vulnerable release of Cisco Secure Firewall ASA or Secure FTD Software and have DTLS flow offload enabled. DTLS flow offload is enabled by default.
- Release N/A (first fixed: 9.20 and earlier / 9.22)
- Release 9.22.3.26 (first fixed: 9.22.3.191 / 9.23.1.195)
- Release 9.23.1.47 (first fixed: 9.23.1.211 / 9.24.1.155)
4 more entries in the full advisory.
- Source-reported fixed versions
- 9.20 and earlier / 9.22
- 9.22.3.191 / 9.23.1.195
- 9.23.1.211 / 9.24.1.155
- 7.6.6
3 more entries in the full advisory.
- Mitigation guidance
- Upgrade to the first fixed release for your train per the Fixed Releases table in this advisory.
- Release N/A: upgrade to 9.20 and earlier / 9.22.
- Release 9.22.3.26: upgrade to 9.22.3.191 / 9.23.1.195.
- Release 9.23.1.47: upgrade to 9.23.1.211 / 9.24.1.155.
4 more entries in the full advisory.
- Workarounds
- There is a workaround that addresses this vulnerability. Use the no flow-offload-dtls CLI command to disable DTLS flow offload.
- Note: For devices that are running Cisco FTD Software, the no flow-offload-dtls command can be pushed using FlexConfig.
- Disabling DTLS flow offload will cause DTLS-encrypted traffic to be processed in software rather than hardware, which may reduce throughput and increase CPU utilization on the affected device. This impact will be more significant in deployments with a high volume of DTLS sessions.
- While this workaround has been deployed and was proven successful in a test environment, customers should determine the applicability and effectiveness in their own environment and under their own use conditions. Customers should be aware that any workaround or mitigation that is implemented may negatively impact the functionality or performance of their network based on intrinsic customer depl…
Android app · Google Play
Monitor future Cisco CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.