Cisco Secure Firewall ASA and FTD Software OSPF Protocol Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software. This vulnerability allows an unauthenticated, adjacent attacker to cause an affected device to reload unexpectedly, leading to a DoS condition. The issue arises from insufficient input validation when processing OSPF update packets, which could be exploited by sending crafted OSPF packets. If OSPF authentication is enabled, the attacker must know the secret key to exploit this vulnerability.

Impact

Exploitation of this vulnerability causes the affected device to reload unexpectedly, resulting in a denial-of-service condition.

Remediation

Cisco has released software updates that address this vulnerability. For instructions on upgrading Cisco Secure FTD Software, refer to the Cisco Secure FMC upgrade guide. To determine the best release to upgrade to, consult the Cisco Secure Firewall Threat Defense Compatibility Guide.

Added: Mar 4, 2026, 7:28 PM
Updated: Mar 4, 2026, 7:28 PM

Vulnerability Rating

Custom Algorithm
spread
6.8
impact
2.5
exploitability
4.9
remediation
7.7
relevance
3.5
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.