CISCO-SA-FTD-TCP-DOS-RHFQNWRG
A vulnerability in the TLS cryptography functionality of the Snort 3 Detection Engine of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to unexpectedly restart, resulting in a denial of service (DoS) condition. This vulnerability is due to improper implementation of the TLS protocol. An attacker could exploit this vulnerability by sending a crafted TLS packet to an affected system. A successful exploit could allow the attacker to cause a device that is running Cisco Secure FTD Software to drop network traffic, resulting in a DoS condition. Note: TLS 1.3 is not affected by this vulnerability. Cisco has released software updates that address this vulnerability. There are workarounds that address this vulnerability. This advisory is part of the March 2026 release of the Cisco Secure Firewall ASA, Secure FMC, and Secure FTD Software Security Advisory Bundled Publication. For a complete list of the advisories and links to them, see Cisco Event Response: March 2026 Semiannual Cisco Secure Firewall ASA, Secure FMC, and Secure FTD Software Security Advisory Bundled Publication ["https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-75736"].
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| 7.2.5.1 | ||
| 7.3.1.1 | ||
| 7.2.8 | ||
| 7.2.0.1 | ||
| 7.2.4.1 | ||
| 7.2.8.1 | ||
| 7.3.1 | ||
| 7.2.3 | ||
| 7.2.6 | ||
| 7.2.9 | ||
| 7.2.5.2 | ||
| 7.3.0 | ||
| 7.2.0 | ||
| 7.2.5 | ||
| 7.2.10.2 | ||
| 7.2.1 | ||
| 7.2.2 | ||
| 7.2.4 | ||
| 7.2.7 | ||
| 7.2.10 |
Timeline
- Mar 4, 2026 CVE Published
References
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-tcp-dos-rHfqnwRg advisory
- https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-75736 url
- https://sec.cloudapps.cisco.com/security/center/resources/security_vulnerability_policy.html url
- https://www.cisco.com/c/en/us/support/docs/security/secure-firewall-threat-defense/220415-determine-the-active-snort-version-that.html url
- https://sec.cloudapps.cisco.com/security/center/softwarechecker.x url
- https://sec.cloudapps.cisco.com/security/center/resources/security_vulnerability_policy.html#asr url
- https://www.cisco.com/c/en/us/support/security/defense-center/products-installation-guides-list.html url
- https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/compatibility/threat-defense-compatibility.html url
- http://www.cisco.com/web/about/security/psirt/security_vulnerability_policy.html url
- https://www.cisco.com/c/en/us/support/index.html url
- https://www.cisco.com/c/en/us/support/web/tsd-cisco-worldwide-contacts.html url
- https://sec.cloudapps.cisco.com/security/center/resources/security_vulnerability_policy.html#fixes url
- https://www.cisco.com/go/psirt url
- https://software.cisco.com fix