cisco-sa-asaftd-dtls-dos-Kp57HkyO: Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software for Secure Firewall 3100 and 4200 Series DTLS Denial of Service Vulnerability
A vulnerability in Datagram TLS (DTLS) message handling of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software for Cisco Secure Firewall 3100 Series and 4200 Series devices could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.This vulnerability is due to improper resource management when processing certain DTLS messages. An attacker could exploit this vulnerability by sending a crafted stream of DTLS traffic to an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.Cisco has released software updates that address this vulnerability. There are workarounds that address this vulnerability.This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-dtls-dos-Kp57HkyOThis advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories. In addition, for further documentation of improvements and fixes in Cisco Secure Firewall products, see Cisco Secure Firewall Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, and Secure Firewall Management Center Software Hardening Release: September 2026.
Affected Software
Event History
Frequently Asked Questions
Which systems are in scope for this issue?
The issue affects Cisco Secure Firewall ASA Software and Cisco Secure Firewall FTD Software running on Cisco Secure Firewall 3100 Series and 4200 Series devices.
What does an attacker need to exploit it?
An unauthenticated remote attacker needs to be able to send a crafted stream of DTLS traffic to an affected device. Successful exploitation can cause the device to reload.
Is a software update available, and are mitigations available if updates cannot be applied immediately?
Cisco has released software updates that address the vulnerability. The advisory also states that workarounds are available.