PT-2025-33323 · Cisco · Cisco Asa+3
Jason Crowder
·
Published
2025-08-14
·
Updated
2025-08-15
·
CVE-2025-20225
CVSS v3.1
5.8
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions:
Cisco IOS Software (affected versions not specified)
Cisco IOS XE Software (affected versions not specified)
Cisco Adaptive Security Appliance (ASA) Software (affected versions not specified)
Cisco Firepower Threat Defense (FTD) Software (affected versions not specified)
Description:
A flaw exists in the Internet Key Exchange Version 2 (IKEv2) feature that may allow a remote attacker to trigger a memory leak, potentially leading to a denial-of-service (DoS) condition. The issue is due to improper processing of IKEv2 packets. In Cisco IOS and IOS XE Software, a successful exploit could cause the device to reload unexpectedly. In Cisco ASA and FTD Software, a successful exploit could lead to partial system memory exhaustion, causing instability and preventing the establishment of new IKEv2 VPN sessions. A manual reboot of the device is required to recover.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Memory Leak
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Asa
Cisco Ftd
Cisco Ios
Cisco Ios Xe