Cisco Secure Firewall ASA and FTD Software OSPF Memory Exhaustion Vulnerability Allowing Denial-of-Service

Vulnerability

A vulnerability exists in the OSPF protocol of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software. This vulnerability could enable an authenticated, adjacent attacker to exhaust memory on an affected device, leading to a denial-of-service (DoS) condition. The issue arises from improper input validation by the OSPF protocol when processing packets. An attacker could exploit this vulnerability by sending crafted OSPF packets to the device, causing memory exhaustion and resulting in a DoS condition.

Impact

Exploitation of this vulnerability leads to memory exhaustion on the affected device, causing it to become unresponsive or unavailable.

Remediation

Cisco has released software updates to address this vulnerability. Instructions for upgrading Cisco Secure FTD devices can be found in the Cisco Secure FMC upgrade guide. For Cisco Secure Firewall ASA, consult the Cisco Secure Firewall ASA Upgrade Guide and Compatibility Matrix.

Added: Mar 4, 2026, 7:26 PM
Updated: Mar 4, 2026, 7:26 PM

Vulnerability Rating

Custom Algorithm
spread
6.8
impact
2.5
exploitability
4.9
remediation
0.0
relevance
3.5
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.