Signed to Unsigned Conversion Error in Cisco Secure Firewall Adaptive Security Appliance (ASA) and Cisco Secure Firewall Threat Defense (FTD) - CVE-2026-20248
Published: September 18, 2026
Vulnerability identifier: #VU150914
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-20248
CWE-ID: CWE-195
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a logic error when parsing a DNS query and tracking the size of the incoming buffers. A remote attacker can cause a denial of service condition on the target system.
Affected software
Cisco Secure Firewall Adaptive Security Appliance (ASA)
Cisco Secure Firewall Threat Defense (FTD)
Cisco Secure Firewall Threat Defense (FTD)
How to mitigate CVE-2026-20248
Install updates from vendor's website.
Cisco Secure Firewall Adaptive Security Appliance (ASA) - addressed in versions 7.0.10, 7.2.12, 7.4.8, 7.6.6, 7.7.13, 9.16.4.103, 9.18.4.94, 9.20.4.49, 9.22.3.26, 9.23.1.47, 9.24.1.26, 10.0.2
Cisco Secure Firewall Threat Defense (FTD) - addressed in versions 7.0.10, 7.2.12, 7.4.8, 7.6.6, 7.7.13, 9.16.4.103, 9.18.4.94, 9.20.4.49, 9.22.3.26, 9.23.1.47, 9.24.1.26, 10.0.2
Cisco Secure Firewall Threat Defense (FTD) - addressed in versions 7.0.10, 7.2.12, 7.4.8, 7.6.6, 7.7.13, 9.16.4.103, 9.18.4.94, 9.20.4.49, 9.22.3.26, 9.23.1.47, 9.24.1.26, 10.0.2