CVE-2026-20006 is a medium-severity denial-of-service vulnerability affecting the Snort 3 Detection Engine within Cisco Secure Firewall Threat Defense (FTD) Software, specifically impacting TLS cryptography functionality (excluding TLS 1.3). An unauthenticated, remote attacker can exploit this flaw by sending a crafted TLS packet, causing the Snort 3 engine to restart and drop network traffic. While the attack complexity is low, leading to a DoS condition, there is currently no public exploit code, active exploitation, or significant community discussion beyond a single mention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Cisco | Cisco Secure Firewall Threat Defense (FTD) Software | 7.2.0, 7.2.0.1, 7.2.1, 7.2.10, 7.2.10.2, 7.2.2, 7.2.3, 7.2.4, 7.2.4.1, 7.2.5, 7.2.5.1, 7.2.5.2, 7.2.6, 7.2.7, 7.2.8, 7.2.8.1, 7.2.9, 7.3.0, 7.3.1, 7.3.1.1, 7.3.1.2, 7.4.0, 7.4.1, 7.4.1.1, 7.4.2, 7.4.2.1, 7.4.2.2, 7.4.2.3, 7.4.2.4, 7.6.0, 7.6.1, 7.6.2, 7.6.2.1CNA affecteddefault unknown |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.