SecBoard
Zurück zur CVE-Übersicht

CVE-2026-20349

HIGH(8.6)KEV — Aktiv ausgenutzt

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

Risk Signal Score52/100 — HOCH
  • CVSS 8.6 — Hoch
  • Im CISA KEV-Katalog (aktiv ausgenutzt)

Erwähnungen (letzte 60 Tage)

Artikel

CISA KEV

Bestätigt ausgenutzt

EPSS-Score

1.0%

Exploit-Wahrscheinlichkeit (30 Tage)

CVSS Score

8.6

Technische Schwere

SecBoard-Einordnung

CVE-2026-20349 ist eine Denial-of-Service (DoS)-Schwachstelle im Remote Access SSL VPN-Dienst der Cisco Adaptive Security Appliance (ASA) Software. Sie ermöglicht einem nicht authentifizierten, entfernten Angreifer, durch das Senden einer speziell präparierten HTTP-Anfrage einen unerwarteten Neustart des Geräts zu verursachen. Die Ursache liegt in einer unzureichenden Fehlerprüfung bei der Verarbeitung von HTTP-Anfragen.

KI-gestützte Einordnung auf Basis der NVD-Daten.

Beschreibung

A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.  This vulnerability is due to insufficient error checking when processing HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.

Erkennung & Indikatoren

Ausnutzung

Aktiv ausgenutzt (CISA KEV).

Behobene Versionen

  • Cisco Secure Firewall ASA Software Release 9.16.1 Hot Fix 89

Threat-Hunting-Queries

Die Schwachstelle betrifft den Remote Access SSL VPN Dienst von Cisco Secure Firewall ASA und FTD. Sie wird durch unzureichende Fehlerprüfung bei der Verarbeitung von HTTP-Anfragen ausgelöst, was zu einem unerwarteten Neustart des Geräts und damit zu einem Denial of Service (DoS) führen kann. Die Detektion sollte sich auf ungewöhnliche Neustarts oder Abstürze von Cisco Secure Firewall ASA/FTD-Gerä

Sentinel/Defender KQL

CiscoASAEvent
| where EventID == "113004" or EventID == "113005" // System reloaded or crashed
| where DeviceProduct == "Cisco ASA" or DeviceProduct == "Cisco FTD"
| summarize Count=count() by DeviceName, DeviceProduct, EventID, bin(TimeGenerated, 1h)
| where Count > 1 // Look for multiple reloads/crashes in a short period
| project TimeGenerated, DeviceName, DeviceProduct, EventID, Count
| extend Threat = "Potential DoS via CVE-2026-20349"
| order by TimeGenerated desc

Splunk SPL

sourcetype=cisco:asa (event_id=113004 OR event_id=113005) OR sourcetype=cisco:ftd (event_id=113004 OR event_id=113005)
| stats count by host, event_id, _time
| where count > 1
| eval threat="Potential DoS via CVE-2026-20349"
| sort -_time

Sigma

title: Cisco ASA/FTD DoS via CVE-2026-20349
status: experimental
description: Detects potential Denial of Service conditions on Cisco Secure Firewall ASA/FTD devices, possibly related to CVE-2026-20349, by monitoring for unexpected reloads or crashes.
references:
  - https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-vpn-dos-dzv4mQFF
logsource:
  product: cisco
  service: asa
detection:
  selection:
    event_id:
      - '113004' # System reloaded
      - '113005' # System crashed
  timeframe: 1h
  condition: selection | count() > 1
level: high

Elastic ES|QL

from cisco.asa.events
| where event.id == "113004" or event.id == "113005"
| summarize event_count = count() by host.name, event.id, span(event.ingested, 1h)
| where event_count > 1
| set threat = "Potential DoS via CVE-2026-20349"
| sort by event.ingested desc

SecBoard-generated · behavioral · requires customization — Von SecBoard erzeugt und nicht in einer Zielumgebung validiert. Vor dem Einsatz an die eigene Protokollierung anpassen.

Betroffene Produkte

  • cpe:2.3:o:cisco:adaptive_security_appliance_software:9.16.1:*:*:*:*:*:*:*
  • cpe:2.3:o:cisco:adaptive_security_appliance_software:9.16.1.28:*:*:*:*:*:*:*
  • cpe:2.3:o:cisco:adaptive_security_appliance_software:9.16.2:*:*:*:*:*:*:*
  • cpe:2.3:o:cisco:adaptive_security_appliance_software:9.16.2.3:*:*:*:*:*:*:*
  • cpe:2.3:o:cisco:adaptive_security_appliance_software:9.16.2.7:*:*:*:*:*:*:*
  • cpe:2.3:o:cisco:adaptive_security_appliance_software:9.16.2.11:*:*:*:*:*:*:*
  • cpe:2.3:o:cisco:adaptive_security_appliance_software:9.16.2.13:*:*:*:*:*:*:*
  • cpe:2.3:o:cisco:adaptive_security_appliance_software:9.16.2.14:*:*:*:*:*:*:*
  • cpe:2.3:o:cisco:adaptive_security_appliance_software:9.16.3:*:*:*:*:*:*:*
  • cpe:2.3:o:cisco:adaptive_security_appliance_software:9.16.3.3:*:*:*:*:*:*:*
  • cpe:2.3:o:cisco:adaptive_security_appliance_software:9.16.3.14:*:*:*:*:*:*:*
  • cpe:2.3:o:cisco:adaptive_security_appliance_software:9.16.3.15:*:*:*:*:*:*:*
  • cpe:2.3:o:cisco:adaptive_security_appliance_software:9.16.3.19:*:*:*:*:*:*:*
  • cpe:2.3:o:cisco:adaptive_security_appliance_software:9.16.3.23:*:*:*:*:*:*:*
  • cpe:2.3:o:cisco:adaptive_security_appliance_software:9.16.4:*:*:*:*:*:*:*
  • cpe:2.3:o:cisco:adaptive_security_appliance_software:9.16.4.9:*:*:*:*:*:*:*
  • cpe:2.3:o:cisco:adaptive_security_appliance_software:9.16.4.14:*:*:*:*:*:*:*
  • cpe:2.3:o:cisco:adaptive_security_appliance_software:9.16.4.19:*:*:*:*:*:*:*
  • cpe:2.3:o:cisco:adaptive_security_appliance_software:9.16.4.27:*:*:*:*:*:*:*
  • cpe:2.3:o:cisco:adaptive_security_appliance_software:9.16.4.38:*:*:*:*:*:*:*

In diesen Analysen erwähnt

Referenzen