
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20013 is a memory exhaustion (memory leak) vulnerability in the IKEv2 feature of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software that allows an unauthenticated, remote attacker to cause a denial-of-service (DoS) condition. The vulnerability was disclosed on March 4, 2026, as part of Cisco's March 2026 Semiannual Cisco Secure Firewall Security Advisory Bundled Publication. Affected ASA versions include 9.18.1–9.18.4.65, 9.19.1–9.20.3.19, 9.22.1.1–9.22.2.3, and 9.23.1–9.23.1.2; affected FTD versions include 7.2.0–7.2.10, 7.3.0–7.4.2, 7.6.0–7.6.3, and 7.7.0–7.7.9. It carries a CVSS v3.1 base score of 5.8 (Medium) (Cisco Advisory).
The root cause is classified as CWE-401 (Missing Release of Memory after Effective Lifetime): the IKEv2 packet processing code fails to free allocated memory, leading to gradual memory exhaustion. An unauthenticated attacker with network access to an affected device's IKEv2 endpoint can send specially crafted IKEv2 packets to trigger the leak; no authentication or user interaction is required. The vulnerability only affects devices where the IKEv2 VPN feature is explicitly enabled (verifiable via show running-config crypto ikev2 | include enable). The vulnerability was discovered internally by Jason Crowder of the Cisco Advanced Security Initiatives Group (ASIG) (Cisco Advisory).
Successful exploitation causes progressive memory exhaustion on the targeted firewall device, ultimately resulting in a DoS condition that requires a manual device reload to recover. Because the scope is marked as Changed (S:C) in the CVSS vector, the DoS condition can also impact the availability of services to other devices elsewhere in the network that rely on the affected firewall. There is no confidentiality or integrity impact; the vulnerability is limited to availability (Cisco Advisory, Feedly).
No public proof-of-concept exploit code is known to exist, and Cisco PSIRT has confirmed no public announcements or malicious use of this vulnerability at the time of disclosure. The EPSS score is approximately 0.094%, indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires only network access and no authentication, lowering the barrier for potential future abuse (Cisco Advisory, Feedly).
show memory or SNMP memory OIDs; device becoming sluggish or unresponsive over time.%ASA-3-211001: Memory allocation Error or similar); IKEv2 negotiation errors logged in the crypto or VPN subsystem.Cisco has released fixed software versions and confirms there are no workarounds available for this vulnerability. Organizations should upgrade to the following minimum fixed releases: ASA Software — 9.18.4.66, 9.20.3.20, 9.22.2.4, or 9.23.1.3; FTD Software — 7.2.11, 7.4.3, 7.6.4, or 7.7.10. As an interim measure, organizations should restrict IKEv2 traffic to trusted source IP addresses using ACLs or upstream filtering, and monitor devices for abnormal memory consumption. Use the Cisco Software Checker tool to confirm exposure and identify the appropriate fixed release for your specific version (Cisco Advisory).
The Center for Internet Security (CIS) issued an advisory noting multiple vulnerabilities in Cisco products from the March 2026 bundled publication, including CVE-2026-20013, flagging potential for remote exploitation (CIS Advisory). Cisco PSIRT attributed discovery to internal researcher Jason Crowder of the Advanced Security Initiatives Group (ASIG), indicating this was found proactively rather than reported externally. Community reaction has been measured given the Medium severity rating and absence of known exploitation, though the unauthenticated attack vector has drawn attention from network security practitioners monitoring perimeter firewall exposure.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."