CVE-2026-20008
published 2026-03-04CVE-2026-20008: A vulnerability in a small subset of CLI commands that are used on Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall…
PriorityP335medium6CVSS 3.1
AVLACLPRHUINSUCHIHAN
EPSS
0.13%
3.1th percentile
A vulnerability in a small subset of CLI commands that are used on Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, local attacker to craft Lua code that could be used on the underlying operating system as root.
This vulnerability exists because user-provided input is not properly sanitized. An attacker could exploit this vulnerability by crafting valid Lua code and submitting it as a malicious parameter for a CLI command. A successful exploit could allow the attacker to inject Lua code, which could lead to arbitrary code execution as the root user. To exploit this vulnerability, an attacker must have valid Administrator credentials.
Affected
233 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | adaptive_security_appliance_software | >= 9.12.1 < 9.16.4.85 | 9.16.4.85 |
| cisco | adaptive_security_appliance_software | >= 9.17.1 < 9.18.4.66 | 9.18.4.66 |
| cisco | adaptive_security_appliance_software | >= 9.19.1 < 9.20.4 | 9.20.4 |
| cisco | adaptive_security_appliance_software | >= 9.22.1.1 < 9.22.2.4 | 9.22.2.4 |
| cisco | adaptive_security_appliance_software | >= 9.23.1 < 9.23.1.7 | 9.23.1.7 |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
CVSS provenance
nvdv3.16.0MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
vendor_cisco6.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Lua Code Injection Vulnerability
vendor_cisco·2026-03-04·CVSS 6.0
CVE-2026-20008 [MEDIUM] CWE-78 Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Lua Code Injection Vulnerability
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Lua Code Injection Vulnerability
A vulnerability in a small subset of CLI commands that are used on Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, local attacker to craft Lua code that could be used on the underlying operating system as root.
This vulnerability exists because user-provided input is not properly sanitized. An attacker could exploit this vulnerability by crafting valid Lua code and submitting it as a malicious parameter for a CLI command. A successful exploit could allow the attacker to inject Lua code, which could lead to arbitrary code execution as the root user. To exploit th
Cisco
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Lua Code Injection Vulnerability
vendor_cisco·CVSS 3.1
CVE-2026-20008 Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Lua Code Injection Vulnerability
CVE-2026-20008: Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Lua Code Injection Vulnerability
A vulnerability in a small subset of CLI commands that are used on Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, local attacker to craft Lua code that could be used on the underlying operating system as root . This vulnerability exists because user-provided input is not properly sanitized. An attacker could exploit this vulnerability by crafting valid Lua code and submitting it as a malicious parameter for a CLI command. A successful exploit could allow the attacker to inject Lua code, which could lead to arbitrary code execution as the root user
GHSA
GHSA-42hx-qv2c-ff49: A vulnerability in a small subset of CLI commands that are used on Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure F
ghsa_unreviewed·2026-03-04
CVE-2026-20008 [MEDIUM] CWE-78 GHSA-42hx-qv2c-ff49: A vulnerability in a small subset of CLI commands that are used on Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure F
A vulnerability in a small subset of CLI commands that are used on Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, local attacker to craft Lua code that could be used on the underlying operating system as root.
This vulnerability exists because user-provided input is not properly sanitized. An attacker could exploit this vulnerability by crafting valid Lua code and submitting it as a malicious parameter for a CLI command. A successful exploit could allow the attacker to inject Lua code, which could lead to arbitrary code execution as the root user. To exploit this vulnerability, an attacker must have valid Administrator credentials.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-03-04
Published