SB20260325183 - Remote denial of service in Cisco IKEv2 implementation on IOS XE, ASA and FTD devices



SB20260325183 - Remote denial of service in Cisco IKEv2 implementation on IOS XE, ASA and FTD devices

Published: March 25, 2026

Security Bulletin ID SB20260325183
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Missing release of memory after effective lifetime (CVE-ID: CVE-2026-20012)

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in the IKEv2 packet parser when handling IKEv2 packets. A remote attacker can send specially crafted IKEv2 packets to an affected device to trigger a memory leak, resulting in a denial of service condition.

A successful exploit on Cisco IOS and IOS XE Software may cause the device to reload, while on Cisco Secure Firewall ASA and FTD Software it may partially exhaust system memory, leading to system instability and requiring a manual reboot to recover.


Remediation

Install update from vendor's website.