In plain language
What this advisory means
A security flaw in certain Cisco Secure Firewall devices can allow an attacker to remotely cause the device to crash and restart, leading to a denial of service. The problem occurs because the firewall mishandles certain encrypted connection messages, using resources improperly. By sending specially crafted traffic, an attacker can exploit this weakness and disrupt firewall operation. Cisco has released software updates and provides a workaround to prevent this issue.
Technical explanation
How the issue affects the environment
This vulnerability exists in the Datagram TLS (DTLS) message handling of Cisco Secure Firewall ASA and FTD Software on 3100 and 4200 Series devices with DTLS flow offload enabled (which is the default setting). Improper resource management during DTLS message processing allows a remote unauthenticated attacker to send a crafted stream of DTLS packets that can trigger the device to reload, causing a denial of service. Disabling DTLS flow offload forces DTLS traffic to be processed in software rather than hardware, mitigating the vulnerability but potentially impacting performance. Cisco recommends upgrading to fixed software releases to remediate the issue permanently.
Operational impact
Why teams should care
Exploitation of this vulnerability can cause affected Cisco Secure Firewall 3100 and 4200 Series devices to reload unexpectedly, resulting in network downtime and service disruption. Since these firewalls protect and control enterprise network traffic, their unexpected reboot can expose organizations to security risks and operational interruptions, potentially affecting business continuity and customer trust.
Immediate action
Cisco strongly recommends upgrading affected devices to the fixed software releases identified in the advisory. The Cisco Software Checker tool can help identify the appropriate fixed version for your device and software release.
Affected and fixed releases
Temporary risk reduction
Disable DTLS flow offload by using the CLI command 'no flow-offload-dtls'. For devices running Cisco FTD Software, this command can be applied via FlexConfig. Note that this workaround may reduce throughput and increase CPU usage, especially under high DTLS traffic loads, so its impact should be evaluated in your environment before deployment.
Evidence and validation checklist
- Cisco Security Advisory published on 2026-09-16 confirming vulnerability details
- Description of vulnerability mechanism as improper resource management in DTLS message processing
- Workaround using 'no flow-offload-dtls' command provided and tested
- Recommendation and availability of fixed software releases
- Cisco Software Checker tool for verifying fixed software
- No known public exploitation reported by Cisco PSIRT
Authoritative reference
Cisco PSIRT Advisories
QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.
