HIGHCVE-2026-20101Published Modified CNA cisco
CVE-2026-20101: A vulnerability in the SAML 2
A vulnerability in the SAML 2.0 single sign-on (SSO) feature of Cisco Secure Firewall ASA Software and Secure FTD Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a DoS condition. This vulnerability is due to insufficient error checking when processing SAML messages. An attacker could exploit this vulnerability by sending crafted SAML messages to the SAML service. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.
Metrics
- CVSS v3.1
- 8.6
- Severity
- HIGH
- Fixed in
- —
- Affected Products
- 2
Affected packages
- Cisco / Cisco Secure Firewall Adaptive Security Appliance (ASA) Software9.12.1 · 9.12.1.2 · 9.12.1.3 · 9.12.2 · 9.12.2.4 · 9.12.2.5
- Cisco / Cisco Secure Firewall Threat Defense (FTD) Software6.4.0 · 6.4.0.1 · 6.4.0.3 · 6.4.0.2 · 6.4.0.4 · 6.4.0.5
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:HReferences