PatchSiren cyber security CVE debrief
CVE-2026-20049 Cisco CVE debrief
A vulnerability in the processing of Galois/Counter Mode (GCM)-encrypted Internet Key Exchange version 2 (IKEv2) IPsec traffic of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to the allocation of an insufficiently sized block of memory. An attacker could exploit this vulnerability by sending crafted GCM-encrypted IPsec traffic to an affected device. A successful exploit could allow the attacker to cause an unexpected reload of the device, resulting in a DoS condition. To exploit this vulnerability, the attacker must have valid credentials to establish a VPN connection with the affected device.
- Vendor
- Cisco
- Product
- Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
- CVSS
- HIGH 7.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-03-04
- Original CVE updated
- 2026-08-11
- Advisory published
- 2026-03-04
- Advisory updated
- 2026-08-11
Who should care
Administrators of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software should review and apply patches to prevent potential denial of service (DoS) attacks.
Technical summary
The vulnerability is caused by the allocation of an insufficiently sized block of memory when processing GCM-encrypted IKEv2 IPsec traffic for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software. An attacker could exploit this vulnerability by sending crafted GCM-encrypted IPsec traffic to an affected device. A successful exploit could allow the attacker to cause an unexpected reload of the device, resulting in a denial of service (DoS) condition. The attacker must have valid credentials to establish a VPN connection with the affected device, and the device must be configured to process GCM-encrypted IKEv2 IPsec traffic. Limited information is available about potential exploits or attacks, but administrators should review and apply patches to prevent potential DoS attacks. The vulnerability affects Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software, and the patches should be applied to prevent potential DoS attacks. Cisco has released patches for this vulnerability, and administrators should review and apply them to affected devices. The vulnerability is due to the allocation of an insufficiently sized block of memory, and the patches address this issue by allocating a properly sized block of memory. The vulnerability can be exploited by sending crafted GCM-encrypted IPsec traffic to an affected device, and a successful exploit could allow the attacker to cause an unexpected reload of the device, resulting in a DoS condition. To exploit this vulnerability, the attacker must have valid credentials to establish a VPN connection with the affected device, and the device must be configured to process GCM-encrypted IKEv2 IPsec traffic. The vulnerability affects Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software, and the patches should be applied to prevent potential DoS attacks. The vulnerability is caused by the allocation of an insufficiently sized block of memory, and the patches address this issue by allocating a properly sized block of memory. The patches 修复
Defensive priority
High priority for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software administrators to review and apply patches
Recommended defensive actions
- Review and apply patches for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software
- Verify VPN connections and monitor for suspicious activity
- Implement compensating controls, such as rate limiting or traffic filtering
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The vulnerability is caused by the allocation of an insufficiently sized block of memory when processing GCM-encrypted IKEv2 IPsec traffic. Limited information is available about potential exploits or attacks.
Official resources
-
CVE-2026-20049 CVE record
CVE.org
-
CVE-2026-20049 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-03-04T18:16:17.863Z and has not been modified since then. The NVD entry is currently Analyzed.