Allocation of Resources Without Limits or Throttling in Cisco Systems, Inc products - CVE-2025-20209
Published: March 13, 2025
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper handling of malformed packets in the Internet Key Exchange version 2 (IKEv2) function. A remote attacker can send specially crafted IKEv2 packets and cause a denial of service condition on the target system.
Affected software
NCS 540L
NCS 1004
NCS 1010
NCS 1014