Medium severity5.8NVD Advisory· Published Mar 4, 2026· Updated Apr 16, 2026
CVE-2026-20015
CVE-2026-20015
Description
A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device that may impact the availability of services to devices elsewhere in the network. This vulnerability is due to a memory leak when parsing IKEv2 packets. An attacker could exploit this vulnerability by sending crafted IKEv2 packets to an affected device. A successful exploit could allow the attacker to exhaust resources, causing a DoS condition that will eventually require the device to be manually reloaded.
Affected products
2- cpe:2.3:a:cisco:firepower_threat_defense_software:*:*:*:*:*:*:*:*Range: >=7.2.0,<7.2.11
- cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:*Range: >=9.18.1,<9.18.4.71
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.