Type conversion in Cisco Firewall Threat Defense (FTD) and Cisco Adaptive Security Appliance (ASA) - CVE-2026-20249

 

Type conversion in Cisco Firewall Threat Defense (FTD) and Cisco Adaptive Security Appliance (ASA) - CVE-2026-20249

Published: September 16, 2026


Vulnerability identifier: #VU150234
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-20249
CWE-ID: CWE-704
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a logic error in the IKEv2 certificate authentication feature when processing a crafted certificate during IKEv2 VPN connection setup. A remote attacker can attempt to establish an IKEv2 VPN connection with a crafted certificate to cause a denial of service.

Only devices with the IKEv2 VPN feature enabled and configured for certificate authentication are affected.


Affected software

Cisco Firewall Threat Defense (FTD)
Cisco Adaptive Security Appliance (ASA)

How to mitigate CVE-2026-20249

Install security update from vendor's website.

Cisco Firewall Threat Defense (FTD) - addressed in versions 7.0.10, 7.2.12, 7.4.8, 7.6.6, 7.7.13
Cisco Adaptive Security Appliance (ASA) - addressed in versions 9.16.4.103, 9.18.4.94, 9.20.4.34, 9.22.3.5, 9.23.1.47, 9.24.1.11, 10.0.2

External References

Related Security Bulletins