Cisco IOS and IOS XE Software Internet Key Exchange Version 2 Denial of Service Vulnerability
Description
Cisco IOS and IOS XE software IKEv2 implementation can be exhausted by crafted SA-Init packets, leading to a denial of service.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Cisco IOS and IOS XE software IKEv2 implementation can be exhausted by crafted SA-Init packets, leading to a denial of service.
Vulnerability
A denial of service vulnerability exists in the Internet Key Exchange Version 2 (IKEv2) implementation in Cisco IOS and IOS XE Software. The issue is due to incorrect handling of crafted IKEv2 SA-Init packets, which can cause the device to reach maximum incoming negotiation limits. An unauthenticated, remote attacker can prevent IKEv2 from establishing new security associations. Affected versions include various releases of Cisco IOS and IOS XE Software prior to the fixed versions indicated in the Cisco Security Advisory [1].
Exploitation
An attacker can exploit this vulnerability by sending crafted IKEv2 SA-Init packets to the targeted device from an unauthenticated, remote network position. No prior authentication or special access is required. The attacker simply sends a sequence of specially crafted packets, which the device processes incorrectly, leading to exhaustion of the negotiation limit.
Impact
Successful exploitation results in a denial of service condition where the affected device is unable to establish new IKEv2 security associations. This can disrupt VPN services or other IKEv2-dependent communications, impacting availability. The confidentiality or integrity of existing associations is not directly affected, but the ability to create new encrypted tunnels is blocked until the device is recovered or the attack stops.
Mitigation
Cisco has released free software updates to address this vulnerability. Customers should upgrade to the fixed software versions indicated in the Cisco Security Advisory [1]. There are no workarounds available that mitigate this issue. The advisory provides detailed instructions for obtaining and installing the updates.
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: n/a
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
1- tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ikev2-9p23Jj2amitrevendor-advisoryx_refsource_CISCO
News mentions
0No linked articles in our index yet.