Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2025-20239 Details

ANALYZED


This CVE record has been analyzed and enriched by NVDAPI.com as an independent party.

Description

A vulnerability in the Internet Key Exchange Version 2 (IKEv2) feature of Cisco IOS Software, IOS XE Software, Secure Firewall Adaptive Security Appliance (ASA) Software, and Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a memory leak, resulting in a denial of service (DoS) condition. This vulnerability is due to a lack of proper processing of IKEv2 packets. An attacker could exploit this vulnerability by sending crafted IKEv2 packets to an affected device. In the case of Cisco IOS and IOS XE Software, a successful exploit could allow the attacker to cause the device to reload unexpectedly. In the case of Cisco ASA and FTD Software, a successful exploit could allow the attacker to partially exhaust system memory, causing system instability such as being unable to establish new IKEv2 VPN sessions. A manual reboot of the device is required to recover from this condition.

Metrics

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-401Missing Release of Memory after Effective Lifetime[email protected]

Affected Products

ProductVersions
Cisco IOS
All versions

CPE

  • cpe:2.3:h:cisco:ios:*:*:*:*:*:*:*:*
  • cpe:2.3:o:cisco:ios:*:*:*:*:*:*:*:*
  • cpe:2.3:a:cisco:ios:*:*:*:*:*:*:*:*

Remediation

  • Workaround:low effort

    Disable the IKEv2 VPN feature on affected devices. To determine if IKEv2 is enabled, use the command "show running-config crypto ikev2 | include enable". If this command returns output, IKEv2 is enabled on at least one interface.

Cisco IOS XE
All versions

CPE

  • cpe:2.3:a:cisco:ios_xe:*:*:*:*:*:*:*:*
  • cpe:2.3:o:cisco:ios_xe:*:*:*:*:*:*:*:*

Remediation

  • Workaround:low effort

    Disable the IKEv2 VPN feature on affected devices. To determine if IKEv2 is enabled, use the command "show running-config crypto ikev2 | include enable". If this command returns output, IKEv2 is enabled on at least one interface.

Cisco Secure Firewall Adaptive Security Appliance
All versions

CPE

  • cpe:2.3:a:cisco:adaptive_security_appliance:*:*:*:*:*:*:*:*
  • cpe:2.3:h:cisco:5500_series_adaptive_security_appliance:*:*:*:*:*:*:*:*
  • cpe:2.3:h:cisco:5500_adaptive_security_appliance:*:*:*:*:*:*:*:*
  • cpe:2.3:h:cisco:adaptive_security_appliance_5540:*:*:*:*:*:*:*:*
  • cpe:2.3:h:cisco:adaptive_security_appliance_5550:*:*:*:*:*:*:*:*
  • cpe:2.3:h:cisco:adaptive_security_appliance_5520:*:*:*:*:*:*:*:*
  • cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:*
  • cpe:2.3:h:cisco:secure_firewall_3105:*:*:*:*:*:*:*:*
  • cpe:2.3:h:cisco:secure_firewall_3120:*:*:*:*:*:*:*:*
  • cpe:2.3:h:cisco:adaptive_security_appliance_5510:*:*:*:*:*:*:*:*
  • cpe:2.3:h:cisco:secure_firewall_3110:*:*:*:*:*:*:*:*

Remediation

  • Workaround:low effort

    Disable the IKEv2 VPN feature on affected devices. To determine if IKEv2 is enabled, use the command "show running-config crypto ikev2 | include enable". If this command returns output, IKEv2 is enabled on at least one interface.

Cisco Secure Firewall Threat Defense
All versions

CPE

  • cpe:2.3:o:cisco:firepower_threat_defense:*:*:*:*:*:*:*:*
  • cpe:2.3:a:cisco:firepower_threat_defense_software:*:*:*:*:*:*:*:*
  • cpe:2.3:a:cisco:firepower_threat_defense:*:*:*:*:*:*:*:*
  • cpe:2.3:a:cisco:firepower_threat_defense_virtual:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

3 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2025-20239
NVD Published Date:
Aug 14, 2025
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2025-20239 Details - Not Deferred