CVE-2026-20249
massUnauthenticated Remote DoS in Cisco ASA/FTD IKEv2 Certificate Authentication
CVE-2026-20249 is a denial-of-service vulnerability in the certificate authentication feature of Internet Key Exchange version 2 (IKEv2) in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software, caused by a logic error (CWE-704) during the certificate authentication phase of IKEv2 connection setup. An unauthenticated, remote attacker can trigger it simply by attempting to establish an IKEv2 VPN connection with a crafted certificate, with no valid credentials or user interaction required. A successful exploit crashes the IKEv2 process, causing the device to reload unexpectedly and producing a denial-of-service condition that disrupts VPN services on the appliance. Any organization running an ASA or FTD VPN gateway with IKEv2 enabled, particularly one exposed to the internet, is potentially affected. As of the advisory data there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and no in-the-wild exploitation is known.
What to do: Upgrade ASA/FTD to a fixed release identified in Cisco's advisory and verified with the Cisco Software Checker (no fixed version numbers are present in the source data). Until patching, limit exposure of UDP 500/4500 to known VPN peers, disable IKEv2 remote access or certificate-based authentication where it is not required, and confirm high-availability/failover is configured to absorb a reload. Monitor devices for unexpected IKEv2 process crashes or reloads and track Cisco PSIRT for updates on exploitation status.
| Cisco Secure Firewall Adaptive Security Appliance (ASA) Software | — |
| Cisco Secure Firewall Threat Defense (FTD) Software | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability in the certification authentication feature of Internet Key Exchange version 2 (IKEv2) for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly. This vulnerability is due to a logic error during the certificate authentication phase of the IKEv2 connection setup. An attacker could exploit this vulnerability by attempting to establish an IKEv2 VPN connection with a crafted certificate. A successful exploit could allow the attacker to cause the IKEv2 process to crash, causing a denial of service (DoS) condition.
- Weakness
- CWE-704
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.