Security Advisory Desk
highQCS priority 100/100Cisco

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software for Secure Firewall 3100 and 4200 Series DTLS Denial of Service Vulnerability

A security flaw in certain Cisco Secure Firewall devices can allow an attacker to remotely cause the device to crash and restart, leading to a denial of service. The problem occurs because the firewall mishandles certain encrypted connection messages, using resources improperly. By sending specially crafted traffic, an attacker can exploit this weakness and disrupt firewall operation. Cisco has released software updates and provides a workaround to prevent this issue.

Published 16/9/2026, 4:00:00 pmVerified 17/9/2026, 5:22:31 amRevision 1
Cisco high network security advisory visual

In plain language

What this advisory means

A security flaw in certain Cisco Secure Firewall devices can allow an attacker to remotely cause the device to crash and restart, leading to a denial of service. The problem occurs because the firewall mishandles certain encrypted connection messages, using resources improperly. By sending specially crafted traffic, an attacker can exploit this weakness and disrupt firewall operation. Cisco has released software updates and provides a workaround to prevent this issue.

Technical explanation

How the issue affects the environment

This vulnerability exists in the Datagram TLS (DTLS) message handling of Cisco Secure Firewall ASA and FTD Software on 3100 and 4200 Series devices with DTLS flow offload enabled (which is the default setting). Improper resource management during DTLS message processing allows a remote unauthenticated attacker to send a crafted stream of DTLS packets that can trigger the device to reload, causing a denial of service. Disabling DTLS flow offload forces DTLS traffic to be processed in software rather than hardware, mitigating the vulnerability but potentially impacting performance. Cisco recommends upgrading to fixed software releases to remediate the issue permanently.

Operational impact

Why teams should care

Exploitation of this vulnerability can cause affected Cisco Secure Firewall 3100 and 4200 Series devices to reload unexpectedly, resulting in network downtime and service disruption. Since these firewalls protect and control enterprise network traffic, their unexpected reboot can expose organizations to security risks and operational interruptions, potentially affecting business continuity and customer trust.

Immediate action

Cisco strongly recommends upgrading affected devices to the fixed software releases identified in the advisory. The Cisco Software Checker tool can help identify the appropriate fixed version for your device and software release.

Affected and fixed releases

Affected versionsCisco Secure Firewall ASA and FTD Software releases with DTLS flow offload enabled prior to the fixed releases
Fixed versionsCisco Secure Firewall ASA and FTD Software fixed releases as listed in Cisco Software Checker

Temporary risk reduction

Disable DTLS flow offload by using the CLI command 'no flow-offload-dtls'. For devices running Cisco FTD Software, this command can be applied via FlexConfig. Note that this workaround may reduce throughput and increase CPU usage, especially under high DTLS traffic loads, so its impact should be evaluated in your environment before deployment.

Evidence and validation checklist

  • Cisco Security Advisory published on 2026-09-16 confirming vulnerability details
  • Description of vulnerability mechanism as improper resource management in DTLS message processing
  • Workaround using 'no flow-offload-dtls' command provided and tested
  • Recommendation and availability of fixed software releases
  • Cisco Software Checker tool for verifying fixed software
  • No known public exploitation reported by Cisco PSIRT

Authoritative reference

Cisco PSIRT Advisories

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source