CVE-2023-20042: Cisco Adaptive Security Appliance Software
High severity, CVSS 8.6. EPSS: 0.7% chance of exploitation in the next 30 days.
A vulnerability in the AnyConnect SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an implementation error within the SSL/TLS session handling process that can prevent the release of a session handler under specific conditions. An attacker could exploit this vulnerability by sending crafted SSL/TLS traffic to an affected device, increasing the probability of session handler leaks. A successful exploit could allow the attacker to eventually deplete the available session handler pool, preventing new sessions from being established and causing a DoS condition.
Affected products
- Cisco Adaptive Security Appliance Software: version 9.16.1 only; version 9.16.1.28 only; version 9.16.2 only; version 9.16.2.3 only; version 9.16.2.7 only; version 9.16.2.11 only; …
- Cisco Secure Firewall Threat Defense: version 7.0.0 only; version 7.0.0.1 only; version 7.0.1 only; version 7.0.1.1 only; version 7.0.2 only; version 7.0.2.1 only; …
Published 2023-11-01. Last modified 2026-08-11.