CVE-2026-20013
published 2026-03-04CVE-2026-20013: A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an unauthenticated, remote attacker to…
PriorityP336medium5.8CVSS 3.1
AVNACLPRNUINSCCNINAL
EPSS
0.30%
22.2th percentile
A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device that may also impact the availability of services to devices elsewhere in the network.
This vulnerability is due to memory exhaustion caused by not freeing memory during IKEv2 packet processing. An attacker could exploit this vulnerability by sending crafted IKEv2 packets to an affected device. A successful exploit could allow the attacker to exhaust resources, causing a DoS condition that will eventually require the device to manually reload.
Affected
233 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | adaptive_security_appliance_software | >= 9.18.1 < 9.18.4.66 | 9.18.4.66 |
| cisco | adaptive_security_appliance_software | >= 9.19.1 < 9.20.3.20 | 9.20.3.20 |
| cisco | adaptive_security_appliance_software | >= 9.22.1.1 < 9.22.2.4 | 9.22.2.4 |
| cisco | adaptive_security_appliance_software | >= 9.23.1 < 9.23.1.3 | 9.23.1.3 |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
CVSS provenance
nvdv3.15.8MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L
vendor_cisco7.7HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software IKEv2 Denial of Service Vulnerabilities
vendor_cisco·2026-03-05·CVSS 7.7
CVE-2026-20013 [HIGH] CWE-401 Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software IKEv2 Denial of Service Vulnerabilities
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software IKEv2 Denial of Service Vulnerabilities
Multiple vulnerabilities in the Internet Key Exchange Version 2 (IKEv2) feature of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow a remote attacker to leak memory when parsing IKEv2 packets, triggering a denial of service (DoS) condition.
For more information about these vulnerabilities, see the Details section of this advisory.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecur
Cisco
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software IKEv2 Denial of Service Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2026-20013 Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software IKEv2 Denial of Service Vulnerabilities
CVE-2026-20013: Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software IKEv2 Denial of Service Vulnerabilities
Multiple vulnerabilities in the Internet Key Exchange Version 2 (IKEv2) feature of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow a remote attacker to leak memory when parsing IKEv2 packets, triggering a denial of service (DoS) condition. For more information about these vulnerabilities, see the
CVSS: 3.1
CWE: CWE-401, CWE-401
Bug IDs: CSCwo49925, CSCwo49926, CSCwq01516, CSCwo49925, CSCwo49926
GHSA
GHSA-mj8r-4vp9-fx97: A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an unauthenticated, remote attack
ghsa_unreviewed·2026-03-04
CVE-2026-20013 [MEDIUM] CWE-401 GHSA-mj8r-4vp9-fx97: A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an unauthenticated, remote attack
A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device that may also impact the availability of services to devices elsewhere in the network.
This vulnerability is due to memory exhaustion caused by not freeing memory during IKEv2 packet processing. An attacker could exploit this vulnerability by sending crafted IKEv2 packets to an affected device. A successful exploit could allow the attacker to exhaust resources, causing a DoS condition that will eventually require the device to manually reload.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-03-04
Published