Executive Summary

CVE-2026-20120 is a logic error in the Object Group Search (OGS) implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software that causes group access control policies to be populated incorrectly, allowing an unauthenticated remote attacker to push traffic that should be denied through the device. Where these firewalls enforce the boundary between IT and OT, the physical consequence is direct: traffic that operators believe is blocked at the enclave edge can reach control system assets.

Technical Exposure Breakdown

The defect sits in how the device builds group access control policies (ACPs) when Object Group Search is enabled. OGS exists to reduce memory consumption on rulesets that reference large object groups, and it does so by evaluating group membership at match time rather than expanding every rule into discrete access control entries. The vulnerability is a fault in that evaluation path. Per the grounding data, it is a logic error in populating ACPs when OGS is configured, and the result is that the deny logic the administrator intended does not hold.

The attack vector is remote and unauthenticated. According to the source, exploitation requires only sending traffic that should be blocked through the device. There is no credential requirement, no session prerequisite, and no described dependency on management plane access. The precondition that matters is configuration state: the device must have OGS enabled and must be using group ACPs. That is not an exotic configuration. OGS is commonly turned on precisely in environments with large, complex rulesets, which describes a segmented OT deployment with many source and destination groups.

The assigned CVSS score is 5.8. That number reflects an access control bypass rather than code execution, but the score understates the operational weight in an OT context. In IT, a filtering gap is one control among many. At an OT enclave boundary, the firewall is frequently the primary and sometimes only enforced separation between corporate networks and process control.

OT Impact and Compliance Risk

The physical risk is not that the firewall crashes. It is that the firewall silently forwards traffic it was configured to deny while continuing to appear healthy. An operator reviewing the ruleset sees the correct deny statements. The device does not enforce them. This is the failure mode that undermines segmentation audits, because the paper configuration and the enforced behavior diverge.

For NERC CIP registered entities, this bears on CIP-005 electronic security perimeter enforcement and CIP-007 for the affected cyber asset. A bypass that permits unauthorized routable traffic across the perimeter is a defensible finding if the exposure is not identified and mitigated. Under IEC 62443, zone and conduit separation is the design assumption that this bug breaks. If the conduit control does not enforce its policy, the zone model is not actually implemented regardless of what the drawings show. Pipeline operators under TSA SD-02C should treat this as a segmentation control failure relevant to their required network segmentation measures. Water and wastewater utilities operating under AWIA 2018 risk and resilience obligations should note that a perimeter firewall silently passing denied traffic invalidates a key assumption in their control inventory.

Compensating Controls

Do not treat vendor patching as the whole answer, and do not run active scans against production firewalls to confirm exposure, since aggressive probing of edge devices can disrupt sessions and controllers behind them.

BreachSpider Intel

BreachSpider tracks CVE-2026-20120 and related perimeter enforcement failures across our database of 350,000+ CVEs and 25,000+ ICS CVEs, and monitors for changes in exploitation and patch status affecting OT boundary devices.