Denial of Service Vulnerability in Cisco Secure Firewall Products
CVE-2025-20224

5.8MEDIUM

Key Information:

Badges

👾 Exploit Exists

What is CVE-2025-20224?

A vulnerability exists in the IKEv2 module of Cisco's Secure Firewall ASA and FTD software, allowing an unauthenticated, remote attacker to exploit this flaw by sending continuously crafted IKEv2 packets. Exploitation of this vulnerability can lead to a memory leak, which may result in denial of service conditions that disrupt system operations, specifically inhibiting the establishment of new IKEv2 VPN sessions. Recovery from such an incident necessitates a manual reboot of the affected device.

Affected Version(s)

Cisco Adaptive Security Appliance (ASA) Software 9.8.1

Cisco Adaptive Security Appliance (ASA) Software 9.8.1.5

Cisco Adaptive Security Appliance (ASA) Software 9.8.1.7

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-20224 : Denial of Service Vulnerability in Cisco Secure Firewall Products