Description
A vulnerability in the system rate-limiting process for syslog message 419002 of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause high CPU utilization on an affected device, resulting in a denial of service (DoS) condition.

This vulnerability is due to improper rate limiting for syslog message 419002. An attacker could exploit this vulnerability by sending a flood of TCP synchronization (SYN) packets to an affected device. A successful exploit could allow the attacker to cause high CPU utilization, resulting in performance degradation. 
Published: 2026-09-16
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via high CPU utilization
Action: Patch Now
AI Analysis

Impact

The vulnerability arises from improper rate limiting for syslog message 419002 in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software. It permits an unauthenticated, remote attacker to flood the device with TCP SYN packets, leading the system to consume excessive CPU resources and degrade performance into a denial of service state. The weakness is classified as CWE-835, indicating that the internal counter or loop logic does not account for input limits, allowing a resource exhaustion scenario.

Affected Systems

This flaw affects Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software. Vulnerable versions are those that have not yet applied the rate‑limiting fix for syslog message 419002; the exact version range is not disclosed in the public advisory.

Risk and Exploitability

The CVSS score of 8.6 points to a high‑severity impact, while the EPSS score of less than 1% indicates a low probability of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. The attack path is straightforward: an unauthenticated attacker sends a SYN flood directed at the device, triggering the flawed rate limiting routine and causing CPU exhaustion. Because the exploit requires only flooding a standard network port with SYN packets, an adversary with network access can readily carry it out without special privileges or software.

Generated by OpenCVE AI on September 18, 2026 at 00:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Threat Defense (FTD) Software that includes the rate‑limiting fix for syslog message 419002.
  • Enable or configure inbound SYN flood protection (e.g., use firewall rules or external DoS mitigation) to limit TCP SYN traffic to the device.
  • Monitor CPU utilization and syslog traffic; configure alerts for abnormal high CPU usage that may indicate a DoS attack.

Generated by OpenCVE AI on September 18, 2026 at 00:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description A vulnerability in the system rate-limiting process for syslog message 419002 of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause high CPU utilization on an affected device, resulting in a denial of service (DoS) condition. This vulnerability is due to improper rate limiting for syslog message 419002. An attacker could exploit this vulnerability by sending a flood of TCP synchronization (SYN) packets to an affected device. A successful exploit could allow the attacker to cause high CPU utilization, resulting in performance degradation.&nbsp;
Title Cisco Secure Firewall Adaptive Security Appliance Software and Secure Firewall Threat Defense Software Logging Denial of Service
Weaknesses CWE-835
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-09-18T19:09:05.715Z

Reserved: 2025-10-08T11:59:15.386Z

Link: CVE-2026-20154

cve-icon Vulnrichment

Updated: 2026-09-18T14:39:39.371Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T21:17:07.723

Modified: 2026-09-18T15:17:06.753

Link: CVE-2026-20154

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T00:45:16Z

Weaknesses
  • CWE-835

    Loop with Unreachable Exit Condition ('Infinite Loop')