Description
A vulnerability in the certification authentication feature of Internet Key Exchange version 2 (IKEv2) for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly.

This vulnerability is due to a logic error during the certificate authentication phase of the IKEv2 connection setup. An attacker could exploit this vulnerability by attempting to establish an IKEv2 VPN connection with a crafted certificate. A successful exploit could allow the attacker to cause the IKEv2 process to crash, causing a denial of service (DoS) condition.
Published: 2026-09-16
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a logic error in the certificate authentication phase of IKEv2 on Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense. An unauthenticated remote attacker can send a crafted certificate during an IKEv2 VPN connection setup, which can cause the IKEv2 process to crash and trigger a device reload. The crash results in a denial of service that affects availability for any users connected to or relying on the firewall. Because the flaw is limited to the authentication step, an attacker cannot gain further access or modify configuration beyond causing the reload.

Affected Systems

The flaw affects Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software. No specific release or build numbers are listed in the advisory, so any device running susceptible versions is potentially impacted.

Risk and Exploitability

The CVSS score of 8.6 indicates a high impact vulnerability, but the EPSS score of less than 1% indicates a very low probability of exploitation in the wild at present, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attacker must initiate an IKEv2 VPN negotiation with a maliciously crafted certificate, which implies a remote network attack vector. Once executed, the crash forces the device to reload, causing a transient denial of service. Based on the description, it is inferred that the vulnerability does not provide authentication or privilege escalation, so the impact is limited to availability only.

Generated by OpenCVE AI on September 18, 2026 at 01:32 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Cisco firmware or patch that addresses the IKEv2 certificate authentication bug.
  • Restrict inbound IKEv2 traffic to trusted VPN peers or enforce strict access policies for VPN connections.
  • Monitor system logs for IKEv2 authentication failures and configure alerts for unexpected IKEv2 process restarts.

Generated by OpenCVE AI on September 18, 2026 at 01:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco adaptive Security Appliance Software
Cisco secure Firewall Threat Defense
Vendors & Products Cisco
Cisco adaptive Security Appliance Software
Cisco secure Firewall Threat Defense

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description A vulnerability in the certification authentication feature of Internet Key Exchange version 2 (IKEv2)&nbsp;for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly. This vulnerability is due to a logic error during the certificate authentication phase of the IKEv2 connection setup. An attacker could exploit this vulnerability by attempting to establish an IKEv2 VPN connection with a crafted certificate. A successful exploit could allow the attacker to cause the IKEv2 process to crash, causing a denial of service (DoS) condition.
Title Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software IKEv2 Certificate Authentication Denial of Service Vulnerability
Weaknesses CWE-704
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H'}


Subscriptions

Cisco Adaptive Security Appliance Software Secure Firewall Threat Defense
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-09-18T19:09:05.719Z

Reserved: 2025-10-08T11:59:15.401Z

Link: CVE-2026-20249

cve-icon Vulnrichment

Updated: 2026-09-18T14:39:34.669Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T21:17:08.517

Modified: 2026-09-18T15:17:06.947

Link: CVE-2026-20249

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:36:09Z

Weaknesses
  • CWE-704

    Incorrect Type Conversion or Cast