Use-after-free in Cisco Systems, Inc products - CVE-2021-40125
Published: October 28, 2021
Vulnerability details
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to a use-after-free error in the Internet Key Exchange Version 2 (IKEv2) implementation. A remote authenticated user can send specially crafted authenticated IKEv2 messages to the affected system, trigger a use-after-free error and perform a denial of service (DoS) attack.
Affected software
Cisco Firewall Threat Defense (FTD)
Cisco Adaptive Security Appliance (ASA)
How to mitigate CVE-2021-40125
Cisco Adaptive Security Appliance (ASA) - addressed in versions 9.8.4.40, 9.12.4.30, 9.14.3.9, 9.15.1.17, 9.16.2