A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall… (CVE-2026-20349)
A vulnerability in the Remote Access SSL VPN service of Cisco Secure Firewall ASA and FTD Software allows an unauthenticated remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS). The issue arises from insufficient error checking when processing HTTP requests. Exploitation involves sending a crafted HTTP request to the affected service, triggering the reload and DoS condition.
AI Analysis
Technical Summary
CVE-2026-20349 is a high-severity vulnerability affecting the Remote Access SSL VPN service in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software. The vulnerability is caused by insufficient error checking during HTTP request processing, which can be exploited by an unauthenticated remote attacker sending a crafted HTTP request. Successful exploitation results in the affected device reloading unexpectedly, causing a denial of service condition. There are no known exploits in the wild at this time, and no patch or remediation details have been provided in the available data.
Potential Impact
The vulnerability allows an unauthenticated remote attacker to cause the affected Cisco firewall devices to reload unexpectedly, resulting in a denial of service (DoS) condition. This disrupts the availability of the firewall service but does not impact confidentiality or integrity according to the CVSS vector.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a patch is available, monitor for unusual HTTP requests targeting the Remote Access SSL VPN service and consider limiting exposure of this service to untrusted networks.
A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall… (CVE-2026-20349)
Description
A vulnerability in the Remote Access SSL VPN service of Cisco Secure Firewall ASA and FTD Software allows an unauthenticated remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS). The issue arises from insufficient error checking when processing HTTP requests. Exploitation involves sending a crafted HTTP request to the affected service, triggering the reload and DoS condition.
CVSS v3.1
Score 8.6high
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-20349 is a high-severity vulnerability affecting the Remote Access SSL VPN service in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software. The vulnerability is caused by insufficient error checking during HTTP request processing, which can be exploited by an unauthenticated remote attacker sending a crafted HTTP request. Successful exploitation results in the affected device reloading unexpectedly, causing a denial of service condition. There are no known exploits in the wild at this time, and no patch or remediation details have been provided in the available data.
Potential Impact
The vulnerability allows an unauthenticated remote attacker to cause the affected Cisco firewall devices to reload unexpectedly, resulting in a denial of service (DoS) condition. This disrupts the availability of the firewall service but does not impact confidentiality or integrity according to the CVSS vector.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a patch is available, monitor for unusual HTTP requests targeting the Remote Access SSL VPN service and consider limiting exposure of this service to untrusted networks.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-8x4j-5v9x-9frv
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-20349"]
- Ecosystems
- []
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6a7c9b72bf8831d539ce080c
Added to database: 08/12/2026, 16:12:34 UTC
Last enriched: 08/12/2026, 17:29:03 UTC
Last updated: 08/13/2026, 02:41:00 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.