---
id: CVE-2020-3298
title: >-
  A vulnerability in the Open Shortest Path First (OSPF) implementation of Cisco
  Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense
  (FTD) Software could allow an unauthenticated, remote attacker to cause the
  relo…
summary: >-
  A vulnerability in the Open Shortest Path First (OSPF) implementation of Cisco
  Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense
  (FTD) Software could allow an unauthenticated, remote attacker to cause the
  relo…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-125
  - CWE-125
vendor: cisco
product: secure_firewall_threat_defense
affected:
  - 'secure_firewall_threat_defense >= 6.2.0, < 6.2.3.16'
  - 'secure_firewall_threat_defense >= 6.3.0, < 6.3.0.6'
  - 'secure_firewall_threat_defense >= 6.4.0, < 6.4.0.9'
  - 'secure_firewall_threat_defense >= 6.5.0, < 6.5.0.5'
  - 'adaptive_security_appliance_software >= 9.6.0, <= 9.6.4.40'
  - 'adaptive_security_appliance_software >= 9.8.0, <= 9.8.4.17'
  - 'adaptive_security_appliance_software >= 9.9.0, <= 9.9.2.66'
  - 'adaptive_security_appliance_software >= 9.10.0, <= 9.10.1.37'
  - 'adaptive_security_appliance_software >= 9.12.0, <= 9.12.3.7'
  - 'adaptive_security_appliance_software >= 9.13.0, <= 9.13.1.7'
patched:
  - secure_firewall_threat_defense 6.5.0.5
published: '2020-05-06'
updated: '2026-08-11'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-3298'
references:
  - url: >-
      https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asa-ftd-ospf-dos-RhMQY8qx
    label: psirt@cisco.com
  - url: >-
      https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asa-ftd-ospf-dos-RhMQY8qx
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.01967
epssPercentile: 0.79496
ingestedAt: '2026-08-11T19:48:27.848Z'
---

## Overview

A vulnerability in the Open Shortest Path First (OSPF) implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to improper memory protection mechanisms while processing certain OSPF packets. An attacker could exploit this vulnerability by sending a series of malformed OSPF packets in a short period of time to an affected device. A successful exploit could allow the attacker to cause a reload of the affected device, resulting in a DoS condition for client traffic that is traversing the device.

## Affected

- `secure_firewall_threat_defense >= 6.2.0, < 6.2.3.16`
- `secure_firewall_threat_defense >= 6.3.0, < 6.3.0.6`
- `secure_firewall_threat_defense >= 6.4.0, < 6.4.0.9`
- `secure_firewall_threat_defense >= 6.5.0, < 6.5.0.5`
- `adaptive_security_appliance_software >= 9.6.0, <= 9.6.4.40`
- `adaptive_security_appliance_software >= 9.8.0, <= 9.8.4.17`
- `adaptive_security_appliance_software >= 9.9.0, <= 9.9.2.66`
- `adaptive_security_appliance_software >= 9.10.0, <= 9.10.1.37`
- `adaptive_security_appliance_software >= 9.12.0, <= 9.12.3.7`
- `adaptive_security_appliance_software >= 9.13.0, <= 9.13.1.7`

## Remediation

Upgrade past the affected range:

- `secure_firewall_threat_defense 6.5.0.5`
