Memory Leak Vulnerability in Cisco IOS and ASA Software Products
CVE-2025-20225

5.8MEDIUM

Key Information:

Badges

👾 Exploit Exists

What is CVE-2025-20225?

A vulnerability exists within the Internet Key Exchange Version 2 (IKEv2) feature of Cisco’s IOS and ASA Software. This flaw can be exploited by unauthenticated remote attackers who send specially crafted IKEv2 packets to affected devices, leading to undesirable effects such as memory leakage and potential denial of service (DoS). For Cisco IOS and IOS XE Software, this could cause unexpected device reloads, while for ASA and Threat Defense Software, attacks may result in the partial exhaustion of system memory, disrupting IKEv2 VPN sessions and overall system stability. Affected devices will require a manual reboot to recover normal operations.

Affected Version(s)

Cisco Adaptive Security Appliance (ASA) Software 9.8.1

Cisco Adaptive Security Appliance (ASA) Software 9.8.1.5

Cisco Adaptive Security Appliance (ASA) Software 9.8.1.7

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-20225 : Memory Leak Vulnerability in Cisco IOS and ASA Software Products