PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-20013 Cisco CVE debrief

A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device that may also impact the availability of services to devices elsewhere in the network. This vulnerability is due to memory exhaustion caused by not freeing memory during IKEv2 packet processing. An attacker could exploit this vulnerability by sending crafted IKEv2 packets to an affected device. A successful exploit could allow the attacker to exhaust resources, causing a DoS condition that will eventually require the device to manually reload.

Vendor
Cisco
Product
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
CVSS
MEDIUM 5.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-03-04
Original CVE updated
2026-08-11
Advisory published
2026-03-04
Advisory updated
2026-08-11

Who should care

Network administrators and security teams managing Cisco Secure Firewall ASA Software and Cisco Secure FTD Software installations should be aware of this vulnerability and take steps to mitigate its impact.

Technical summary

The vulnerability is due to memory exhaustion caused by not freeing memory during IKEv2 packet processing in Cisco Secure Firewall ASA Software and Cisco Secure FTD Software. An unauthenticated, remote attacker could exploit this by sending crafted IKEv2 packets to cause a DoS condition on an affected device, potentially impacting network service availability. This could allow the attacker to exhaust resources, causing a DoS condition that will eventually require the device to manually reload. Network administrators and security teams managing Cisco Secure Firewall ASA Software and Cisco Secure FTD Software installations should be aware of this vulnerability and take steps to mitigate its impact.

Defensive priority

Medium priority given the potential for service disruption and the availability of patches.

Recommended defensive actions

  • Apply patches provided by Cisco for affected versions of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software.
  • Implement network segmentation to limit the impact of a potential DoS condition.
  • Monitor network traffic for suspicious IKEv2 packet activity.
  • Consider implementing rate limiting for IKEv2 traffic.
  • Regularly review and update firewall configurations to ensure optimal security posture.

Evidence notes

The vulnerability is caused by memory exhaustion due to not freeing memory during IKEv2 packet processing. An attacker could exploit this by sending crafted IKEv2 packets to an affected device, potentially causing a DoS condition. Cisco has provided patches for affected versions.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-03-04T18:16:15.113Z and has not been modified since then.