CVE-2026-20022 describes a denial-of-service vulnerability in Cisco Secure Firewall ASA Software and Cisco Secure FTD Software, specifically affecting the OSPF protocol when canonicalization debugging is enabled. An unauthenticated, adjacent attacker can trigger a device reload by sending crafted OSPF LSU packets due to insufficient input validation. This vulnerability is rated Medium (CVSS 6.1) due to its adjacent attack vector and high impact on availability, but it requires high attack complexity. There is currently no evidence of active exploitation, public exploit code, or significant community discussion beyond initial reporting.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.12.1CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:9.12.1:*:*:*:*:*:*:* | ||
9.12.1.2CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:9.12.1.2:*:*:*:*:*:*:* | ||
9.12.1.3CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:9.12.1.3:*:*:*:*:*:*:* | ||
9.12.2CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:9.12.2:*:*:*:*:*:*:* | ||
9.12.2.1CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:9.12.2.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.