CVE-2026-20101

HIGH

Cisco Secure Firewall ASA/FTD - DoS

Title source: llm
STIX 2.1

Description

A vulnerability in the SAML 2.0 single sign-on (SSO) feature of Cisco Secure Firewall ASA Software and Secure FTD Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a DoS condition. This vulnerability is due to insufficient error checking when processing SAML messages. An attacker could exploit this vulnerability by sending crafted SAML messages to the SAML service. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.

Scores

CVSS v3 8.6
EPSS 0.0015
EPSS Percentile 35.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-330
Status published
Products (2)
cisco/adaptive_security_appliance_software 9.12.1 - 9.16.4.85
cisco/firepower_threat_defense_software 6.4.0 - 7.0.9
Published Mar 04, 2026
Tracked Since Mar 05, 2026