Cisco Secure Firewall ASA and FTD Software VPN Web Server Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software. This vulnerability allows an unauthenticated, remote attacker to cause a DoS condition on the affected device. The issue arises from ineffective memory management in the VPN web server, which can be exploited by sending a large number of crafted HTTP requests. A successful exploit may cause the device to reload, leading to a DoS condition.

Impact

Exploitation of this vulnerability causes the affected device to reload, creating a denial-of-service condition.

Remediation

Cisco has released software updates to address this vulnerability. For instructions on upgrading Cisco Secure FTD devices, refer to the Cisco Secure FMC upgrade guide. To determine the best release to upgrade to, consult the Cisco Secure Firewall Threat Defense Compatibility Guide.

Added: Mar 4, 2026, 6:51 PM
Updated: Mar 4, 2026, 6:51 PM

Vulnerability Rating

Custom Algorithm
spread
6.8
impact
2.5
exploitability
7.8
remediation
7.7
relevance
3.5
threat
0.0
urgency
2.9
incentive
8.3

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.