Junglewise Threat Intelligence

CVE-2026-20013: Cisco Secure Firewall ASA and FTD IKEv2 memory leak denial of service

CVE-2026-20013 · Severity: medium · CVSS 5.8 · Published 2026-03-04

Technologies: Cisco Secure Firewall ASA Software, Cisco Secure Firewall Threat Defense Software. Vendors: Cisco.

Executive brief

Cisco Secure Firewall ASA and FTD are network security appliances that protect corporate networks using VPN capabilities. A vulnerability in their IKEv2 VPN feature allows an unauthenticated remote attacker to send specially crafted packets that exhaust device memory, causing the firewall to crash and require manual restart. This disrupts VPN connectivity and network protection for all devices relying on that firewall.

Technical details

CVE-2026-20013 is a memory leak vulnerability in the IKEv2 packet processing code of Cisco Secure Firewall ASA and FTD software. The root cause is improper memory management that fails to free memory during IKEv2 packet processing, leading to memory exhaustion over time. An unauthenticated remote attacker can exploit this by sending crafted IKEv2 packets to an affected device with IKEv2 VPN enabled, requiring no authentication or user interaction. A successful exploit exhausts system resources and causes a denial of service condition, eventually requiring manual device reload. The vulnerability is mitigated by Cisco software updates; no workarounds are available.

Affected products

  • Cisco Secure Firewall ASA Software <UNKNOWN>
  • Cisco Secure Firewall Threat Defense Software <UNKNOWN>

Timeline

  • 2026-03-04: disclosed

References

Related threats