DoS Vulnerability in Cisco Secure Firewall ASA and FTD Software
CVE-2026-20014
7.7HIGH
What is CVE-2026-20014?
A vulnerability exists in the IKEv2 functionality of Cisco Secure Firewall ASA and FTD software, enabling authenticated remote attackers with valid VPN credentials to send crafted IKEv2 packets. This could exploit weaknesses in IKEv2 packet handling, leading to memory exhaustion and potentially causing the affected device to reload. Such a denial-of-service condition could disrupt the availability of services for other devices in the network.
Affected Version(s)
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.18.1
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.18.1.3
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.18.2