CVE-2026-20013
Cisco Adaptive Security Appliance (ASA) vulnerability analysis and mitigation

Overview

CVE-2026-20013 is a memory exhaustion (memory leak) vulnerability in the IKEv2 feature of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software that allows an unauthenticated, remote attacker to cause a denial-of-service (DoS) condition. The vulnerability was disclosed on March 4, 2026, as part of Cisco's March 2026 Semiannual Cisco Secure Firewall Security Advisory Bundled Publication. Affected ASA versions include 9.18.1–9.18.4.65, 9.19.1–9.20.3.19, 9.22.1.1–9.22.2.3, and 9.23.1–9.23.1.2; affected FTD versions include 7.2.0–7.2.10, 7.3.0–7.4.2, 7.6.0–7.6.3, and 7.7.0–7.7.9. It carries a CVSS v3.1 base score of 5.8 (Medium) (Cisco Advisory).

Technical details

The root cause is classified as CWE-401 (Missing Release of Memory after Effective Lifetime): the IKEv2 packet processing code fails to free allocated memory, leading to gradual memory exhaustion. An unauthenticated attacker with network access to an affected device's IKEv2 endpoint can send specially crafted IKEv2 packets to trigger the leak; no authentication or user interaction is required. The vulnerability only affects devices where the IKEv2 VPN feature is explicitly enabled (verifiable via show running-config crypto ikev2 | include enable). The vulnerability was discovered internally by Jason Crowder of the Cisco Advanced Security Initiatives Group (ASIG) (Cisco Advisory).

Impact

Successful exploitation causes progressive memory exhaustion on the targeted firewall device, ultimately resulting in a DoS condition that requires a manual device reload to recover. Because the scope is marked as Changed (S:C) in the CVSS vector, the DoS condition can also impact the availability of services to other devices elsewhere in the network that rely on the affected firewall. There is no confidentiality or integrity impact; the vulnerability is limited to availability (Cisco Advisory, Feedly).

Exploitability

No public proof-of-concept exploit code is known to exist, and Cisco PSIRT has confirmed no public announcements or malicious use of this vulnerability at the time of disclosure. The EPSS score is approximately 0.094%, indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires only network access and no authentication, lowering the barrier for potential future abuse (Cisco Advisory, Feedly).

Exploitation steps

  1. Reconnaissance: Identify internet-facing Cisco ASA or FTD devices with IKEv2 enabled using network scanning tools (e.g., Shodan, Censys, or nmap targeting UDP/500 and UDP/4500 — standard IKEv2 ports).
  2. Confirm IKEv2 availability: Send standard IKEv2 IKE_SA_INIT packets to the target and observe responses to confirm the IKEv2 service is active.
  3. Craft malicious IKEv2 packets: Construct IKEv2 packets designed to trigger the memory allocation path that fails to free memory. These packets do not require authentication and can be sent as part of the IKE_SA_INIT exchange.
  4. Flood the target: Repeatedly send the crafted IKEv2 packets to the affected device to progressively exhaust available memory resources.
  5. Achieve DoS: After sufficient memory exhaustion, the device becomes unresponsive and eventually requires a manual reload, disrupting VPN and firewall services for all dependent network devices (Cisco Advisory).

Indicators of compromise

  • Network: Unusual volume of IKEv2 packets (UDP/500 or UDP/4500) from one or more external source IPs targeting the firewall; repeated IKE_SA_INIT messages without completing the handshake.
  • Device Behavior: Gradual increase in memory utilization on the ASA/FTD device observable via show memory or SNMP memory OIDs; device becoming sluggish or unresponsive over time.
  • Logs: Syslog messages indicating memory allocation failures or low-memory warnings (e.g., %ASA-3-211001: Memory allocation Error or similar); IKEv2 negotiation errors logged in the crypto or VPN subsystem.
  • Operational: Unexpected device reload requiring manual intervention; VPN tunnels dropping without clear configuration or peer-side cause (Cisco Advisory).

Mitigation and workarounds

Cisco has released fixed software versions and confirms there are no workarounds available for this vulnerability. Organizations should upgrade to the following minimum fixed releases: ASA Software — 9.18.4.66, 9.20.3.20, 9.22.2.4, or 9.23.1.3; FTD Software — 7.2.11, 7.4.3, 7.6.4, or 7.7.10. As an interim measure, organizations should restrict IKEv2 traffic to trusted source IP addresses using ACLs or upstream filtering, and monitor devices for abnormal memory consumption. Use the Cisco Software Checker tool to confirm exposure and identify the appropriate fixed release for your specific version (Cisco Advisory).

Community reactions

The Center for Internet Security (CIS) issued an advisory noting multiple vulnerabilities in Cisco products from the March 2026 bundled publication, including CVE-2026-20013, flagging potential for remote exploitation (CIS Advisory). Cisco PSIRT attributed discovery to internal researcher Jason Crowder of the Advanced Security Initiatives Group (ASIG), indicating this was found proactively rather than reported externally. Community reaction has been measured given the Medium severity rating and absence of known exploitation, though the unauthenticated attack vector has drawn attention from network security practitioners monitoring perimeter firewall exposure.

Additional resources


SourceThis report was generated using AI

Related Cisco Adaptive Security Appliance (ASA) vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-20349HIGH8.6
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:o:cisco:adaptive_security_appliance_software
YesYesAug 11, 2026
CVE-2026-20012HIGH8.6
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:a:cisco:firepower_threat_defense
NoYesMar 25, 2026
CVE-2026-20025MEDIUM6.8
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:o:cisco:adaptive_security_appliance_software
NoYesMar 04, 2026
CVE-2026-20023MEDIUM6.5
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:o:cisco:adaptive_security_appliance_software
NoYesMar 04, 2026
CVE-2026-20024MEDIUM5.7
  • Cisco Adaptive Security Appliance (ASA) logoCisco Adaptive Security Appliance (ASA)
  • cpe:2.3:o:cisco:adaptive_security_appliance_software
NoYesMar 04, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management