Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software IKEv2 Certificate Authentication Denial of Service Vulnerability
Cisco patched an ASA/FTD IKEv2 certificate authentication flaw letting unauthenticated remote attackers crash the IKEv2 process and reload devices with crafted certificates.
A logic error during the certificate authentication phase of IKEv2 connection setup in Cisco Secure Firewall ASA and FTD Software allows an unauthenticated, remote attacker to crash the IKEv2 process. Exploitation involves attempting to establish an IKEv2 VPN connection with a crafted certificate, causing a denial of service through an unexpected device reload. Cisco has released software updates.