Cisco IOS, IOS XE, Secure Firewall Adaptive Security Appliance, and Secure Firewall Threat Defense Software IKEv2 Denial of Service Vulnerabilities

🚨 SEVERITY: HIGH — CVSS 8.6 Security Advisory

TL;DR 📌

Cisco has identified multiple high-severity vulnerabilities in the IKEv2 feature of Cisco IOS, IOS XE, Secure Firewall ASA, and Secure Firewall FTD software that could allow unauthenticated remote attackers to trigger denial of service (DoS) conditions. Software updates are available to address these vulnerabilities.

What happened 🕵️‍♂️

Cisco has released an advisory detailing several vulnerabilities in the Internet Key Exchange Version 2 (IKEv2) feature across various Cisco software platforms. These vulnerabilities can be exploited by unauthenticated remote attackers to cause devices to reload or trigger memory leaks, leading to a denial of service condition.

Affected products 🖥️

The vulnerabilities affect the following Cisco products when the IKEv2 VPN feature is enabled:

  • Cisco IOS Software
  • Cisco IOS XE Software
  • Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
  • Cisco Secure Firewall Threat Defense (FTD) Software

Note: The Group Encrypted Transport VPN (GET VPN) feature is not affected.

Fixed software 🔧

Upgrade to the first fixed release in your train (or later):

Release / Product First Fixed Release Notes
1.0 Initial public release.

Workarounds 🧯

There are no workarounds available to mitigate these vulnerabilities.

Risk in context 🎯

The highest CVSS score for these vulnerabilities is 8.6, categorizing them as High severity. The vulnerabilities are exploitable from the internet without authentication, allowing attackers to potentially disrupt service availability. Immediate patching is recommended to mitigate risks.

Fast facts ⚡

  • Vulnerabilities: CVE-2025-20224, CVE-2025-20225, CVE-2025-20239, CVE-2025-20252, CVE-2025-20253, CVE-2025-20254
  • Severity: Highest CVSS score of 8.6 (High)
  • Impact: Denial of service conditions
  • Exploitation: Unauthenticated remote access required
  • Workarounds: None available

For leadership 🧭

Executive summary. Any Cisco router, switch or firewall running IOS, IOS XE, ASA or FTD with IKEv2 VPN turned on can be knocked offline remotely by someone with no credentials at all. There is no workaround, so the only fix is upgrading, and this should be scheduled as a priority given these devices typically sit at the network edge.

Why it matters:

  • The affected feature, IKEv2, is the VPN negotiation protocol used for remote access and site-to-site tunnels on IOS, IOS XE, ASA and FTD – exactly the boxes that terminate connections from the internet.
  • No authentication is required to trigger the six flaws, so exposure is limited only by whether IKEv2 is enabled and reachable, not by having valid VPN credentials.
  • Impact ranges from a device reload to a memory leak, both of which take down VPN connectivity and, on ASA/FTD, potentially firewall inspection along with it.
  • Cisco has published no workaround, which means mitigation is limited to disabling IKEv2 where it isn’t needed or applying the fixed software.

Now / Next / Later:

  • Now: Identify every IOS, IOS XE, ASA and FTD device with IKEv2 VPN enabled and check its software version against Cisco’s fixed releases for these six CVEs.
  • Next: Schedule upgrades to the first fixed release for each affected train in your next change window, prioritising internet-facing VPN termination points; disable IKEv2 in the interim on any device that doesn’t strictly need it.
  • Later: Build IKEv2/VPN-facing Cisco devices into a regular patch cadence tied to Cisco security advisories, since no workaround was available here and timely upgrading was the only mitigation.