CVE-2025-20254: Cisco Adaptive Security Appliance ASA Software

Medium severity, CVSS 5.8. EPSS: 0.4% chance of exploitation in the next 30 days.

A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a memory leak, resulting in a denial of service (DoS) condition. This vulnerability is due to improper parsing of IKEv2 packets. An attacker could exploit this vulnerability by sending a continuous stream of crafted IKEv2 packets to an affected device. A successful exploit could allow the attacker to partially exhaust system memory, causing system instability like being unable to establish new IKEv2 VPN sessions. A manual reboot of the device is required to recover from this condition.

Affected products

  • Cisco Cisco Adaptive Security Appliance ASA Software: version 9.12.1 only; version 9.12.1.2 only; version 9.12.1.3 only; version 9.12.2 only; version 9.12.2.4 only; version 9.12.2.5 only; …
  • Cisco Cisco Firepower Threat Defense Software: version 6.2.3 only; version 6.2.3.1 only; version 6.2.3.2 only; version 6.2.3.3 only; version 6.2.3.4 only; version 6.2.3.5 only; …

Published 2025-08-14. Last modified 2026-06-17.