CVE-2026-20049
published 2026-03-04CVE-2026-20049: A vulnerability in the processing of Galois/Counter Mode (GCM)-encrypted Internet Key Exchange version 2 (IKEv2) IPsec traffic of Cisco Secure Firewall…
PriorityP344high7.7CVSS 3.1
AVNACLPRLUINSCCNINAH
EPSS
0.29%
21.2th percentile
A vulnerability in the processing of Galois/Counter Mode (GCM)-encrypted Internet Key Exchange version 2 (IKEv2) IPsec traffic of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to the allocation of an insufficiently sized block of memory. An attacker could exploit this vulnerability by sending crafted GCM-encrypted IPsec traffic to an affected device. A successful exploit could allow the attacker to cause an unexpected reload of the device, resulting in a DoS condition. To exploit this vulnerability, the attacker must have valid credentials to establish a VPN connection with the affected device.
Affected
205 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | adaptive_security_appliance_software | >= 9.18.1 < 9.18.4.66 | 9.18.4.66 |
| cisco | adaptive_security_appliance_software | >= 9.19.1 < 9.20.3.20 | 9.20.3.20 |
| cisco | adaptive_security_appliance_software | >= 9.22.1.1 < 9.22.2.4 | 9.22.2.4 |
| cisco | adaptive_security_appliance_software | >= 9.23.1 < 9.23.1.3 | 9.23.1.3 |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
| cisco | cisco_secure_firewall_adaptive_security_appliance_software | — | — |
CVSS provenance
nvdv3.17.7HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
vendor_cisco7.7HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4wgv-wwff-cw37: A vulnerability in the processing of Galois/Counter Mode (GCM)-encrypted Internet Key Exchange version 2 (IKEv2) IPsec traffic of Cisco Secure Firewal
ghsa_unreviewed·2026-03-04
CVE-2026-20049 [HIGH] CWE-131 GHSA-4wgv-wwff-cw37: A vulnerability in the processing of Galois/Counter Mode (GCM)-encrypted Internet Key Exchange version 2 (IKEv2) IPsec traffic of Cisco Secure Firewal
A vulnerability in the processing of Galois/Counter Mode (GCM)-encrypted Internet Key Exchange version 2 (IKEv2) IPsec traffic of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to the allocation of an insufficiently sized block of memory. An attacker could exploit this vulnerability by sending crafted GCM-encrypted IPsec traffic to an affected device. A successful exploit could allow the attacker to cause an unexpected reload of the device, resulting in a DoS condition. To exploit this vulnerability, the attacker must have valid credentials to establish a VPN connection with the
Cisco
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software IPsec Denial of Service Vulnerability
vendor_cisco·2026-03-05·CVSS 7.7
CVE-2026-20049 [HIGH] CWE-131 Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software IPsec Denial of Service Vulnerability
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software IPsec Denial of Service Vulnerability
A vulnerability in the processing of Galois/Counter Mode (GCM)-encrypted Internet Key Exchange version 2 (IKEv2) IPsec traffic of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to the allocation of an insufficiently sized block of memory. An attacker could exploit this vulnerability by sending crafted GCM-encrypted IPsec traffic to an affected device. A successful exploit could allow the attacker to cause an unexpected reload of the device, resulti
Cisco
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software IPsec Denial of Service Vulnerability
vendor_cisco·CVSS 3.1
CVE-2026-20049 Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software IPsec Denial of Service Vulnerability
CVE-2026-20049: Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software IPsec Denial of Service Vulnerability
A vulnerability in the processing of Galois/Counter Mode (GCM)-encrypted Internet Key Exchange version 2 (IKEv2) IPsec traffic of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to the allocation of an insufficiently sized block of memory. An attacker could exploit this vulnerability by sending crafted GCM-encrypted IPsec traffic to an affected device. A successful exploit could allow the attacker to cause an unexpected reload of the d
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-03-04
Published