Denial of Service Vulnerability in Cisco Secure Firewall Products
CVE-2025-20224
5.8MEDIUM
What is CVE-2025-20224?
A vulnerability exists in the IKEv2 module of Cisco's Secure Firewall ASA and FTD software, allowing an unauthenticated, remote attacker to exploit this flaw by sending continuously crafted IKEv2 packets. Exploitation of this vulnerability can lead to a memory leak, which may result in denial of service conditions that disrupt system operations, specifically inhibiting the establishment of new IKEv2 VPN sessions. Recovery from such an incident necessitates a manual reboot of the affected device.
Affected Version(s)
Cisco Adaptive Security Appliance (ASA) Software 9.8.1
Cisco Adaptive Security Appliance (ASA) Software 9.8.1.5
Cisco Adaptive Security Appliance (ASA) Software 9.8.1.7