ZeroHour

CVE-2026-20249

mass

Unauthenticated Remote DoS in Cisco ASA/FTD IKEv2 Certificate Authentication

CVSS 3.1
8.6 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-20249 is a denial-of-service vulnerability in the certificate authentication feature of Internet Key Exchange version 2 (IKEv2) in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software, caused by a logic error (CWE-704) during the certificate authentication phase of IKEv2 connection setup. An unauthenticated, remote attacker can trigger it simply by attempting to establish an IKEv2 VPN connection with a crafted certificate, with no valid credentials or user interaction required. A successful exploit crashes the IKEv2 process, causing the device to reload unexpectedly and producing a denial-of-service condition that disrupts VPN services on the appliance. Any organization running an ASA or FTD VPN gateway with IKEv2 enabled, particularly one exposed to the internet, is potentially affected. As of the advisory data there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and no in-the-wild exploitation is known.

What to do: Upgrade ASA/FTD to a fixed release identified in Cisco's advisory and verified with the Cisco Software Checker (no fixed version numbers are present in the source data). Until patching, limit exposure of UDP 500/4500 to known VPN peers, disable IKEv2 remote access or certificate-based authentication where it is not required, and confirm high-availability/failover is configured to absorb a reload. Monitor devices for unexpected IKEv2 process crashes or reloads and track Cisco PSIRT for updates on exploitation status.

Affected
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
Cisco Secure Firewall Threat Defense (FTD) Software
Estimated exposure
massplausibly >1M users served by hundreds of thousands of deployed ASA/FTD appliances; public internet scans have long shown on the order of 300,000+ Cisco ASA… — ASA/FTD is one of the most widely deployed enterprise firewall/VPN platforms and public scan data (Shodan/Censys-style banner counts) shows hundreds of thousands of Cisco ASA devices internet-visible, with IKEv2 remote-access VPN a core,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in the certification authentication feature of Internet Key Exchange version 2 (IKEv2) for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly. This vulnerability is due to a logic error during the certificate authentication phase of the IKEv2 connection setup. An attacker could exploit this vulnerability by attempting to establish an IKEv2 VPN connection with a crafted certificate. A successful exploit could allow the attacker to cause the IKEv2 process to crash, causing a denial of service (DoS) condition.

Weakness
CWE-704
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.