#VU57759 Use-after-free in Cisco Systems, Inc products - CVE-2021-40125
Published: October 28, 2021
ASA 5500-X Series Firewalls
Cisco Adaptive Security Appliance (ASA)
Cisco Firewall Threat Defense (FTD)
Cisco Systems, Inc
Description
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to a use-after-free error in the Internet Key Exchange Version 2 (IKEv2) implementation. A remote authenticated user can send specially crafted authenticated IKEv2 messages to the affected system, trigger a use-after-free error and perform a denial of service (DoS) attack.