Memory Leak Vulnerability in Cisco IOS and ASA Software Products
CVE-2025-20225
What is CVE-2025-20225?
A vulnerability exists within the Internet Key Exchange Version 2 (IKEv2) feature of Cisco’s IOS and ASA Software. This flaw can be exploited by unauthenticated remote attackers who send specially crafted IKEv2 packets to affected devices, leading to undesirable effects such as memory leakage and potential denial of service (DoS). For Cisco IOS and IOS XE Software, this could cause unexpected device reloads, while for ASA and Threat Defense Software, attacks may result in the partial exhaustion of system memory, disrupting IKEv2 VPN sessions and overall system stability. Affected devices will require a manual reboot to recover normal operations.
Affected Version(s)
Cisco Adaptive Security Appliance (ASA) Software 9.8.1
Cisco Adaptive Security Appliance (ASA) Software 9.8.1.5
Cisco Adaptive Security Appliance (ASA) Software 9.8.1.7