Executive brief
Cisco Secure Firewall devices (ASA and FTD) used to protect networks and enforce security policies contain a memory allocation flaw in IPsec encryption processing. An authenticated attacker with VPN credentials can send specially crafted encrypted traffic to crash the firewall, causing service outages and disrupting network connectivity and security enforcement.
Technical details
This vulnerability is an insufficient buffer allocation flaw (CWE-131) in the processing of Galois/Counter Mode (GCM)-encrypted IKEv2 IPsec traffic. When a Cisco Secure Firewall ASA or FTD device is configured with GCM encryption for IPsec IKEv2 proposals (aes-gcm, aes-gcm-192, or aes-gcm-256), the device allocates an undersized memory block to handle incoming encrypted traffic. An authenticated attacker with valid VPN credentials can exploit this by sending crafted GCM-encrypted IPsec packets to the device, triggering a buffer overflow that causes an unexpected device reload (denial of service). Exploitation requires network access to the VPN endpoint and valid authentication credentials. Cisco has released fixed software versions; no workarounds are available.
Affected products
- Cisco Secure Firewall Adaptive Security Appliance (ASA) Software Multiple versions; see vendor advisory for affected releases
- Cisco Secure Firewall Threat Defense (FTD) Software Multiple versions; see vendor advisory for affected releases
Timeline
- 2026-03-04: disclosed: Cisco security advisory published