CVE-2020-3554: Cisco Adaptive Security Appliance
High severity, CVSS 7.5. EPSS: 2.7% chance of exploitation in the next 30 days.
A vulnerability in the TCP packet processing of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a memory exhaustion condition. An attacker could exploit this vulnerability by sending a high rate of crafted TCP traffic through an affected device. A successful exploit could allow the attacker to exhaust device resources, resulting in a DoS condition for traffic transiting the affected device.
Affected products
- Cisco Adaptive Security Appliance: before 9.12.4.3 (fixed in 9.12.4.3)
- Cisco Adaptive Security Appliance Software: from 9.13.0, before 9.13.1.13 (fixed in 9.13.1.13); from 9.14.0, before 9.14.1.30 (fixed in 9.14.1.30)
- Cisco Secure Firewall Threat Defense: up to and including 6.2.2; from 6.3.0, before 6.4.0.10 (fixed in 6.4.0.10); from 6.5.0, before 6.5.0.5 (fixed in 6.5.0.5); version 6.6.0 only
Published 2020-10-21. Last modified 2026-08-11.