CVE-2026-20015

EUVD-2026-9432
A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device that may impact the availability of services to devices elsewhere in the network.

 This vulnerability is due to a memory leak when parsing IKEv2 packets. An attacker could exploit this vulnerability by sending crafted IKEv2 packets to an affected device. A successful exploit could allow the attacker to exhaust resources, causing a DoS condition that will eventually require the device to be manually reloaded.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.8 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
ciscoadaptive_security_appliance_software
9.18.1 ≤
𝑥
< 9.18.4.71
ciscoadaptive_security_appliance_software
9.19.1 ≤
𝑥
< 9.20.4.10
ciscoadaptive_security_appliance_software
9.22.1.1 ≤
𝑥
< 9.22.2.13
ciscoadaptive_security_appliance_software
9.23.1 ≤
𝑥
< 9.23.1.19
ciscofirepower_threat_defense_software
7.2.0 ≤
𝑥
< 7.2.11
ciscofirepower_threat_defense_software
7.3.0 ≤
𝑥
< 7.4.3
ciscofirepower_threat_defense_software
7.6.0 ≤
𝑥
< 7.6.4
ciscofirepower_threat_defense_software
7.7.0 ≤
𝑥
< 7.7.11
𝑥
= Vulnerable software versions