PatchSiren cyber security CVE debrief
CVE-2026-20013 Cisco CVE debrief
A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device that may also impact the availability of services to devices elsewhere in the network. This vulnerability is due to memory exhaustion caused by not freeing memory during IKEv2 packet processing. An attacker could exploit this vulnerability by sending crafted IKEv2 packets to an affected device. A successful exploit could allow the attacker to exhaust resources, causing a DoS condition that will eventually require the device to manually reload.
- Vendor
- Cisco
- Product
- Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
- CVSS
- MEDIUM 5.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-03-04
- Original CVE updated
- 2026-08-11
- Advisory published
- 2026-03-04
- Advisory updated
- 2026-08-11
Who should care
Network administrators and security teams managing Cisco Secure Firewall ASA Software and Cisco Secure FTD Software installations should be aware of this vulnerability and take steps to mitigate its impact.
Technical summary
The vulnerability is due to memory exhaustion caused by not freeing memory during IKEv2 packet processing in Cisco Secure Firewall ASA Software and Cisco Secure FTD Software. An unauthenticated, remote attacker could exploit this by sending crafted IKEv2 packets to cause a DoS condition on an affected device, potentially impacting network service availability. This could allow the attacker to exhaust resources, causing a DoS condition that will eventually require the device to manually reload. Network administrators and security teams managing Cisco Secure Firewall ASA Software and Cisco Secure FTD Software installations should be aware of this vulnerability and take steps to mitigate its impact.
Defensive priority
Medium priority given the potential for service disruption and the availability of patches.
Recommended defensive actions
- Apply patches provided by Cisco for affected versions of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software.
- Implement network segmentation to limit the impact of a potential DoS condition.
- Monitor network traffic for suspicious IKEv2 packet activity.
- Consider implementing rate limiting for IKEv2 traffic.
- Regularly review and update firewall configurations to ensure optimal security posture.
Evidence notes
The vulnerability is caused by memory exhaustion due to not freeing memory during IKEv2 packet processing. An attacker could exploit this by sending crafted IKEv2 packets to an affected device, potentially causing a DoS condition. Cisco has provided patches for affected versions.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-20013 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-20013
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-20013 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-20013
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ikev2-dos-eBueGdEG
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.