CVE-2026-20015: Medium severity Cisco Secure Firewall ASA Software vulnerability
A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device that may impact the availability of services to devices elsewhere in the network. This vulnerability is due to a memory leak when parsing IKEv2 packets. An attacker could exploit this vulnerability by sending crafted IKEv2 packets to an affected device. A successful exploit could allow the attacker to exhaust resources, causing a DoS condition that will eventually require the device to be manually reloaded.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20015?
CVE-2026-20015 has a high severity rating due to its potential to allow unauthenticated attackers to cause a denial-of-service condition.
How do I fix CVE-2026-20015?
To fix CVE-2026-20015, upgrade to the latest versions of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software as recommended in the security advisory.
What are the affected products for CVE-2026-20015?
The affected products for CVE-2026-20015 include Cisco Secure Firewall ASA Software and Cisco Secure FTD Software.
Can CVE-2026-20015 be exploited remotely?
Yes, CVE-2026-20015 can be exploited by an unauthenticated, remote attacker.
What impact does CVE-2026-20015 have on network services?
CVE-2026-20015 can impact the availability of services across the network, potentially affecting multiple devices.