CVE-2026-20222: Cisco Secure Adaptive Security Appliance Software and Secure Firewall Threat Defense Software EIGRP Denial of Service Vulnerability
A vulnerability in the EIGRP implementation in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to improper resource management when handling EIGRP update messages. An attacker could exploit this vulnerability by sending crafted EIGRP updates at a high rate to an affected device. A successful exploit could allow the attacker to trigger a memory leak that will eventually cause the affected device to reload unexpectedly.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An unauthenticated attacker with adjacent network access to an affected device can exploit it. The attacker does not need valid credentials or user interaction.
What traffic is required for exploitation?
The attacker must send crafted EIGRP update messages to the affected device at a high rate. The messages trigger improper resource management and a memory leak.
What is the operational impact of a successful attack?
Memory consumption can increase until the device reloads unexpectedly. This causes a denial-of-service condition rather than a disclosed confidentiality or integrity impact.