CVE-2026-20101
A vulnerability in the SAML 2.0 single sign-on (SSO) feature of Cisco Secure Firewall ASA Software and Secure FTD Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a DoS condition. This vulnerability is due to insufficient error checking when processing SAML messages. An attacker could exploit this vulnerability by sending crafted SAML messages to the SAML service. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.6
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
- EPSS probability
- 0.35%
- CWE
- CWE-330
- Published
- 2026-03-04
- Last modified
- 2026-03-12
Affected products
- Cisco Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
- Cisco Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
- Cisco Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
- Cisco Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
- Cisco Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
- Cisco Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
- Cisco Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
- Cisco Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
Weakness type
Related vulnerabilities
- CVE-2026-53939 — OpenIDC/cjose uses all-zero Content Encryption Key for AES-CBC-HMAC JWE encryption
- CVE-2026-86187 — WWBN AVideo Weak PRNG Password Generation via External Login
- CVE-2026-17274 — IBM i is Affected By Multiple Vulnerabilities in Debug Server
- CVE-2026-3416 — Predictable Pseudorandom Number Generation via Webhook HMAC Secret Generation in Multiple WSO2 Products Allows Forged Event Payloads
- CVE-2026-66047 — ProfilePress WordPress Plugin < 4.17.2 Unauthenticated Arbitrary Plugin Installation RCE
- CVE-2026-81852 — AshAdmin ships a hardcoded CSP nonce, allowing nonce-based CSP bypass
- CVE-2026-82555 — TOTOLINK N600R Authentication cstecgi.cgi loginAuth random values
- CVE-2026-19485 — Bucket Squatting in Vertex AI Search for Commerce