CVE-2026-20050 PUBLISHED CVSS 6.800000190734863 MEDIUM

A vulnerability in the Do Not Decrypt exclusion feature of the SSL decryption feature of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper memory management during the inspection of TLS 1.2 encrypted traffic. An attacker could exploit this vulnerability by sending crafted TLS 1.2 encrypted traffic through an affected device. A successful exploit could allow the attacker to cause a reload of an affected device. Note: This vulnerability only affects traffic that is encrypted by TLS 1.2. Other versions of TLS are not affected.

EPSS 0.14% · 33.9th percentile

Risk Scores

CVSS v3.1
6.800000190734863
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H
EPSS Score
0.14%
33.9th percentile

Affected Products

VendorProductVersions
CiscoCisco Secure Firewall Threat Defense (FTD) Software7.0.0, 7.0.0.1, 7.0.1

Timeline

References

Open in Interactive Console →