CVE-2020-3179High· 7.5▾ TwilightA vulnerability in the generic routing encapsulation (GRE) tunnel decapsulation feature of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an a…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.4 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 11.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.9%
1.9% → 2.0%
A vulnerability in the generic routing encapsulation (GRE) tunnel decapsulation feature of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a memory handling error when GRE over IPv6 traffic is processed. An attacker could exploit this vulnerability by sending crafted GRE over IPv6 packets with either IPv4 or IPv6 payload through an affected device. A successful exploit could allow the attacker to cause the device to crash, resulting in a DoS condition.
secure_firewall_threat_defense >= 6.3.0, < 6.3.0.5secure_firewall_threat_defense >= 6.4.0, < 6.4.0.6asa_5505_firmware = 9.9(2)asa_5505_firmware = 101.5(1.26)asa_5510_firmware = 9.9(2)asa_5510_firmware = 101.5(1.26)asa_5512-x_firmware = 9.9(2)asa_5512-x_firmware = 101.5(1.26)asa_5515-x_firmware = 9.9(2)asa_5515-x_firmware = 101.5(1.26)asa_5520_firmware = 9.9(2)asa_5520_firmware = 101.5(1.26)asa_5525-x_firmware = 9.9(2)asa_5525-x_firmware = 101.5(1.26)asa_5540_firmware = 9.9(2)asa_5540_firmware = 101.5(1.26)asa_5545-x_firmware = 9.9(2)asa_5545-x_firmware = 101.5(1.26)asa_5550_firmware = 9.9(2)asa_5550_firmware = 101.5(1.26)asa_5555-x_firmware = 9.9(2)asa_5555-x_firmware = 101.5(1.26)asa_5580_firmware = 9.9(2)asa_5580_firmware = 101.5(1.26)asa_5585-x_firmware = 9.9(2)asa_5585-x_firmware = 101.5(1.26)Upgrade past the affected range:
secure_firewall_threat_defense 6.4.0.6Connected by shared product, vendor, weakness, or advisory.
CVE-2018-0101Critical· 10.0A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause a reload of the affected system or to remotely execute c…
CVE-2025-20224Medium· 5.8A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker t…
CVE-2026-20012High· 8.6A vulnerability in the Internet Key Exchange version 2 (IKEv2) feature of Cisco IOS Software, Cisco IOS XE Software, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, and Cisco Secure Firewall Threat Defense (FTD) Softwar…
CVE-2026-20135High· 8.6A vulnerability in the TLS 1.3 implementation in Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (Do…
CVE-2026-20052Medium· 5.8A vulnerability in the memory management handling for the Snort 3 Detection Engine of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart. …
CVE-2026-20007Medium· 5.8A vulnerability in the Snort 2 and Snort 3 deep packet inspection of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured Snort rules and allow traffic onto the network …