CVE-2026-20015

A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device that may impact the availability of services to devices elsewhere in the network. This vulnerability is due to a memory leak when parsing IKEv2 packets. An attacker could exploit this vulnerability by sending crafted IKEv2 packets to an affected device. A successful exploit could allow the attacker to exhaust resources, causing a DoS condition that will eventually require the device to be manually reloaded.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:*
cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:*
cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:*
cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:cisco:firepower_threat_defense_software:*:*:*:*:*:*:*:*
cpe:2.3:a:cisco:firepower_threat_defense_software:*:*:*:*:*:*:*:*
cpe:2.3:a:cisco:firepower_threat_defense_software:*:*:*:*:*:*:*:*
cpe:2.3:a:cisco:firepower_threat_defense_software:*:*:*:*:*:*:*:*

History

16 Apr 2026, 20:02

Type Values Removed Values Added
References () https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ikev2-dos-eBueGdEG - () https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ikev2-dos-eBueGdEG - Vendor Advisory
First Time Cisco firepower Threat Defense Software
Cisco
Cisco adaptive Security Appliance Software
CPE cpe:2.3:a:cisco:firepower_threat_defense_software:*:*:*:*:*:*:*:*
cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:*
Summary
  • (es) Una vulnerabilidad en la función IKEv2 de Cisco Secure Firewall ASA Software y Cisco Secure FTD Software podría permitir a un atacante remoto no autenticado causar una condición DoS en un dispositivo afectado que podría impactar la disponibilidad de los servicios a dispositivos en otras partes de la red. Esta vulnerabilidad se debe a una fuga de memoria al analizar paquetes IKEv2. Un atacante podría explotar esta vulnerabilidad enviando paquetes IKEv2 manipulados a un dispositivo afectado. Un exploit exitoso podría permitir al atacante agotar los recursos, causando una condición DoS que eventualmente requerirá que el dispositivo sea recargado manualmente.

04 Mar 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-04 18:16

Updated : 2026-04-16 20:02


NVD link : CVE-2026-20015

Mitre link : CVE-2026-20015

CVE.ORG link : CVE-2026-20015


JSON object : View

Products Affected

cisco

  • firepower_threat_defense_software
  • adaptive_security_appliance_software
CWE
CWE-401

Missing Release of Memory after Effective Lifetime