Denial of Service Vulnerability in Cisco IOS, IOS XE, and Secure Firewall Products
CVE-2025-20253

8.6HIGH

Key Information:

Badges

👾 Exploit Exists

What is CVE-2025-20253?

A vulnerability in the IKEv2 feature of Cisco IOS Software, IOS XE Software, Secure Firewall ASA Software, and Secure FTD Software enables an unauthenticated remote attacker to trigger a denial of service condition. This can occur due to improper processing of IKEv2 packets, allowing an attacker to send specially crafted packets that could lead to an infinite loop, exhausting resources and causing the affected device to reload unexpectedly.

Affected Version(s)

Cisco Adaptive Security Appliance (ASA) Software 9.12.3

Cisco Adaptive Security Appliance (ASA) Software 9.8.3

Cisco Adaptive Security Appliance (ASA) Software 9.12.1

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-20253 : Denial of Service Vulnerability in Cisco IOS, IOS XE, and Secure Firewall Products