CVE-2026-20073 PUBLISHED CVSS 5.800000190734863 MEDIUM

A vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to send traffic that should be denied through an affected device. This vulnerability is due to improper error handling when an affected device that is joining a cluster runs out of memory while replicating access control rules. An attacker could exploit this vulnerability by sending traffic that should be blocked through the device. A successful exploit could allow the attacker to bypass access controls and reach devices in protected networks.

EPSS 0.07% · 20.0th percentile

Risk Scores

CVSS v3.1
5.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
EPSS Score
0.07%
20.0th percentile

Affected Products

VendorProductVersions
CiscoCisco Secure Firewall Threat Defense (FTD) Software6.4.0.1, 6.4.0.2, 6.4.0.5
CiscoCisco Secure Firewall Adaptive Security Appliance (ASA) Software9.12.4.55, 9.18.2.8, 9.16.4.14

Timeline

References

Open in Interactive Console →