CVE-2020-3528: Cisco Adaptive Security Appliance
High severity, CVSS 7.5. EPSS: 1.4% chance of exploitation in the next 30 days.
A vulnerability in the OSPF Version 2 (OSPFv2) implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to incomplete input validation when the affected software processes certain OSPFv2 packets with Link-Local Signaling (LLS) data. An attacker could exploit this vulnerability by sending a malformed OSPFv2 packet to an affected device. A successful exploit could allow the attacker to cause an affected device to reload, resulting in a DoS condition.
Affected products
- Cisco Adaptive Security Appliance: before 9.6 (fixed in 9.6)
- Cisco Adaptive Security Appliance Software: from 9.8.0, before 9.8.4.26 (fixed in 9.8.4.26); from 9.9.0, before 9.9.2.80 (fixed in 9.9.2.80); from 9.10.0, before 9.10.1.44 (fixed in 9.10.1.44); from 9.12.0, before 9.12.4.4 (fixed in 9.12.4.4); from 9.13.0, before 9.13.1.13 (fixed in 9.13.1.13); from 9.14.0, before 9.14.1.19 (fixed in 9.14.1.19)
- Cisco Secure Firewall Threat Defense: before 6.3.0.6 (fixed in 6.3.0.6); from 6.4.0, before 6.4.0.10 (fixed in 6.4.0.10); from 6.5.0, before 6.5.0.5 (fixed in 6.5.0.5); from 6.6.0, before 6.6.1 (fixed in 6.6.1)
Published 2020-10-21. Last modified 2026-08-11.