Cisco Secure Firewall Threat Defense Do Not Decrypt Policy Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in Cisco Secure Firewall Threat Defense (FTD) Software. This issue arises in the Do Not Decrypt exclusion feature of the SSL decryption capability, affecting devices that are configured to exclude certain traffic from decryption. The vulnerability is linked to improper memory management when inspecting TLS 1.2 encrypted traffic. An unauthenticated, remote attacker could exploit this flaw by sending crafted TLS 1.2 traffic through the affected device, potentially causing the device to reload and disrupt services. Notably, this vulnerability does not impact other versions of TLS.

Impact

Exploitation of this vulnerability leads to a denial-of-service condition, causing the affected device to reload and temporarily disrupt services.

Remediation

Cisco has released software updates to address this vulnerability. For instructions on upgrading Cisco Secure FTD devices, refer to the Cisco Secure FMC upgrade guide. To determine the best release to upgrade to, consult the Cisco Secure Firewall Threat Defense Compatibility Guide.

Added: Mar 4, 2026, 7:34 PM
Updated: Mar 4, 2026, 7:34 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
2.5
exploitability
7.8
remediation
7.7
relevance
3.5
threat
0.0
urgency
2.9
incentive
8.3

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.