Impact
The vulnerability is a logic error in the certificate authentication phase of IKEv2 on Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense. An unauthenticated remote attacker can send a crafted certificate during an IKEv2 VPN connection setup, which can cause the IKEv2 process to crash and trigger a device reload. The crash results in a denial of service that affects availability for any users connected to or relying on the firewall. Because the flaw is limited to the authentication step, an attacker cannot gain further access or modify configuration beyond causing the reload.
Affected Systems
The flaw affects Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software. No specific release or build numbers are listed in the advisory, so any device running susceptible versions is potentially impacted.
Risk and Exploitability
The CVSS score of 8.6 indicates a high impact vulnerability, but the EPSS score of less than 1% indicates a very low probability of exploitation in the wild at present, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attacker must initiate an IKEv2 VPN negotiation with a maliciously crafted certificate, which implies a remote network attack vector. Once executed, the crash forces the device to reload, causing a transient denial of service. Based on the description, it is inferred that the vulnerability does not provide authentication or privilege escalation, so the impact is limited to availability only.
OpenCVE Enrichment