---
cve: "CVE-2026-20336"
severity: "HIGH"
cvss: 8.8
epss: "21.7%"
vendor: "Cisco"
kev: false
exploited: false
published: "2026-09-16 21:17:11"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-19T17:28:13+02:00"
---

# CVE-2026-20336

> 8.8 HIGH

## Beschreibung

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.

The vulnerabilities tracked by CVE-2026-20336 are related to issues concerning improper control of a resource through its lifetime that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-664.

## CVSS-Vektor

```
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Benachbart | warn |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Schwachstellen-Klasse

- **CWE-664** — Improper Control of a Resource Through its Lifetime
  The product does not maintain or incorrectly maintains control over a resource throughout its lifetime of creation, use, and release.

## Angriffsmuster (CAPEC)

- [CAPEC-21 — Exploitation of Trusted Identifiers](https://capec.mitre.org/data/definitions/21.html) _(Severity: High)_
- [CAPEC-60 — Reusing Session IDs (aka Session Replay)](https://capec.mitre.org/data/definitions/60.html) _(Severity: High)_
- [CAPEC-61 — Session Fixation](https://capec.mitre.org/data/definitions/61.html) _(Severity: High)_
- [CAPEC-62 — Cross Site Request Forgery](https://capec.mitre.org/data/definitions/62.html) _(Severity: Very High)_
- [CAPEC-196 — Session Credential Falsification through Forging](https://capec.mitre.org/data/definitions/196.html) _(Severity: Medium)_

## ATT&CK-Techniken

- [T1134 — Access Token Manipulation](https://attack.mitre.org/techniques/T1134/)
- [T1528 — Steal Application Access Token](https://attack.mitre.org/techniques/T1528/)
- [T1539 — Steal Web Session Cookie](https://attack.mitre.org/techniques/T1539/)
- [T1134.001 — Access Token Manipulation:Token Impersonation/Theft](https://attack.mitre.org/techniques/T1134/001/)
- [T1550.004 — Use Alternate Authentication Material:Web Session Cookie](https://attack.mitre.org/techniques/T1550/004/)
- [T1134.002 — Access Token Manipulation: Create Process with Token](https://attack.mitre.org/techniques/T1134/002/)
- [T1134.003 — Access Token Manipulation: Make and Impersonate Token](https://attack.mitre.org/techniques/T1134/003/)
- [T1606 — Forge Web Credentials](https://attack.mitre.org/techniques/T1606/)

## Referenzen

- <https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-asaftdfmc-uvpPROhN>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-20336) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
