Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability
Act NowCVSS 8.6cisco-sa-asaftd-vpn-dos-dzv4mQFFAug 11, 2026
CiscoEnergyManufacturing
IT in OT - Cisco networking products are commonly deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary
A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall ASA and FTD Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly. The vulnerability is due to insufficient error checking when processing HTTP requests. An attacker could send a crafted HTTP request to the Remote Access SSL VPN service on an affected device, causing it to reload and resulting in a denial of service condition.
What this means
What could happen
An attacker on the network can force your firewall to reboot by sending a specially crafted request to the SSL VPN service, taking your firewall offline and blocking all traffic until it restarts. This directly interrupts network and operational access for your facility.
Who's at risk
Energy and manufacturing facilities relying on Cisco Secure Firewall appliances (ASA 5500-X, Firepower 1000/2100/4100/9000 Series, 3000 ISA, Secure Firewall 200/1200/3100/4200/6100 Series, and virtual appliances) for network perimeter security and SSL VPN remote access. This affects any organization using these firewalls for remote worker access or managing industrial control system networks.
How it could be exploited
An attacker sends a malformed HTTP request to the SSL VPN endpoint on the firewall (port 443 by default). The firewall fails to properly validate the request, crashes, and reboots. No authentication is required; the attacker only needs network access to the firewall's SSL VPN port.
Prerequisites
- Network access to port 443 (or configured SSL VPN port) on the firewall
- SSL VPN service enabled on the firewall
Remotely exploitableNo authentication requiredLow complexity attackActively exploited (KEV)High CVSS score (8.6)Affects network security boundaries
Exploitability
Actively exploited — confirmed by CISA KEV
Affected products (13)
13 with fix
ProductAffected VersionsFix Status
Firepower 2100 SeriesAll versionsFix available
Firepower 1000 SeriesAll versionsFix available
ASA 5500-X Series FirewallsAll versionsFix available
3000 Series Industrial Security Appliances (ISA)All versionsFix available
Firepower 9000 SeriesAll versionsFix available
Firepower 4100 SeriesAll versionsFix available
Adaptive Security Virtual Appliance (ASAv)All versionsFix available
Secure Firewall 3100 SeriesAll versionsFix available
Remediation & Mitigation
0/14
Do now
0/14Firepower 2100 Series
HOTFIXUpdate Firepower 2100 Series to patched firmware version
Firepower 1000 Series
HOTFIXUpdate Firepower 1000 Series to patched firmware version
3000 Series Industrial Security Appliances (ISA)
HOTFIXUpdate 3000 Series Industrial Security Appliances (ISA) to patched firmware version
HARDENINGRestrict network access to the SSL VPN port (443 or configured port) to authorized users and networks only; disable SSL VPN service if not actively used
Firepower 9000 Series
HOTFIXUpdate Firepower 9000 Series to patched firmware version
Firepower 4100 Series
HOTFIXUpdate Firepower 4100 Series to patched firmware version
Adaptive Security Virtual Appliance (ASAv)
HOTFIXUpdate ASAv (virtual appliance) to patched software version
Secure Firewall 3100 Series
HOTFIXUpdate Secure Firewall 3100 Series to patched firmware version
Secure Firewall 4200 Series
HOTFIXUpdate Secure Firewall 4200 Series to patched firmware version
Secure Firewall 1200 Series
HOTFIXUpdate Secure Firewall 1200 Series to patched firmware version
Secure Firewall 200 Series
HOTFIXUpdate Secure Firewall 200 Series to patched firmware version
Secure Firewall 6100 Series
HOTFIXUpdate Secure Firewall 6100 Series to patched firmware version
Secure Firewall Threat Defense Virtual
HOTFIXUpdate Secure Firewall Threat Defense Virtual to patched software version
All products
HOTFIXUpdate ASA 5500-X Series to patched firmware version
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/323f68e8-cf37-424b-89f0-f97f79e1507fGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.