Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability

What is CVE-2026-20349?

Original source data

A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. 

This vulnerability is due to insufficient error checking when processing HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.

Verify to continue the analysis

A short verification protects the vulnerability source and prevents automated AI abuse.

Overview

Original source data

A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. 

This vulnerability is due to insufficient error checking when processing HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.

Affected products and scope

CyStack is analyzing this vulnerability. The page will update automatically when the analysis is ready.

Technical details

CyStack is analyzing this vulnerability. The page will update automatically when the analysis is ready.

Exploitability

CyStack is analyzing this vulnerability. The page will update automatically when the analysis is ready.

Technical impact

CyStack is analyzing this vulnerability. The page will update automatically when the analysis is ready.

Business impact

CyStack is analyzing this vulnerability. The page will update automatically when the analysis is ready.

Remediation

CyStack is analyzing this vulnerability. The page will update automatically when the analysis is ready.

Detection

CyStack is analyzing this vulnerability. The page will update automatically when the analysis is ready.
Sources (4)
Learn more

Run an in-depth assessment with complete web risk management

CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.

Explore CyStack VulnScan
CyStack VulnScan dashboard