PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-20049 Cisco CVE debrief

A vulnerability in the processing of Galois/Counter Mode (GCM)-encrypted Internet Key Exchange version 2 (IKEv2) IPsec traffic of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to the allocation of an insufficiently sized block of memory. An attacker could exploit this vulnerability by sending crafted GCM-encrypted IPsec traffic to an affected device. A successful exploit could allow the attacker to cause an unexpected reload of the device, resulting in a DoS condition. To exploit this vulnerability, the attacker must have valid credentials to establish a VPN connection with the affected device.

Vendor
Cisco
Product
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
CVSS
HIGH 7.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-03-04
Original CVE updated
2026-08-11
Advisory published
2026-03-04
Advisory updated
2026-08-11

Who should care

Administrators of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software should review and apply patches to prevent potential denial of service (DoS) attacks.

Technical summary

The vulnerability is caused by the allocation of an insufficiently sized block of memory when processing GCM-encrypted IKEv2 IPsec traffic for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software. An attacker could exploit this vulnerability by sending crafted GCM-encrypted IPsec traffic to an affected device. A successful exploit could allow the attacker to cause an unexpected reload of the device, resulting in a denial of service (DoS) condition. The attacker must have valid credentials to establish a VPN connection with the affected device, and the device must be configured to process GCM-encrypted IKEv2 IPsec traffic. Limited information is available about potential exploits or attacks, but administrators should review and apply patches to prevent potential DoS attacks. The vulnerability affects Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software, and the patches should be applied to prevent potential DoS attacks. Cisco has released patches for this vulnerability, and administrators should review and apply them to affected devices. The vulnerability is due to the allocation of an insufficiently sized block of memory, and the patches address this issue by allocating a properly sized block of memory. The vulnerability can be exploited by sending crafted GCM-encrypted IPsec traffic to an affected device, and a successful exploit could allow the attacker to cause an unexpected reload of the device, resulting in a DoS condition. To exploit this vulnerability, the attacker must have valid credentials to establish a VPN connection with the affected device, and the device must be configured to process GCM-encrypted IKEv2 IPsec traffic. The vulnerability affects Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software, and the patches should be applied to prevent potential DoS attacks. The vulnerability is caused by the allocation of an insufficiently sized block of memory, and the patches address this issue by allocating a properly sized block of memory. The patches 修复

Defensive priority

High priority for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software administrators to review and apply patches

Recommended defensive actions

  • Review and apply patches for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software
  • Verify VPN connections and monitor for suspicious activity
  • Implement compensating controls, such as rate limiting or traffic filtering
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The vulnerability is caused by the allocation of an insufficiently sized block of memory when processing GCM-encrypted IKEv2 IPsec traffic. Limited information is available about potential exploits or attacks.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-03-04T18:16:17.863Z and has not been modified since then. The NVD entry is currently Analyzed.