Executive brief
Cisco Secure Firewall ASA and Secure Firewall Threat Defense (FTD) software, which protect corporate networks via VPN, contain memory leak vulnerabilities in their IKEv2 (Internet Key Exchange Version 2) feature. An unauthenticated remote attacker can send specially crafted packets to exhaust device memory, causing the firewall to become unresponsive and require manual restart, disrupting VPN services and potentially impacting network availability across the organization.
Technical details
The vulnerability is a memory leak (CWE-401) in the IKEv2 packet parsing logic of Cisco ASA and FTD software. When processing crafted IKEv2 packets, the affected code fails to properly free allocated memory during packet handling, leading to progressive memory exhaustion. The attack is unauthenticated and network-reachable, requiring only IKEv2 to be enabled on an interface; an attacker sends a stream of malformed IKEv2 packets to trigger the leak. Upon successful exploitation, memory is exhausted, causing a denial of service that requires manual device reload. Cisco has released software patches to address this vulnerability; no workarounds are available.
Affected products
- Cisco Secure Firewall ASA Software <UNKNOWN>
- Cisco Secure Firewall Threat Defense Software <UNKNOWN>
Timeline
- 2026-03-04: disclosed