CVE-2021-40125

medium Cisco
CVSS v3 Base Score
5.3
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Score
1.0%
Exploitation probability in 30 days
Top 41% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Confidentiality
None
Integrity
None
Availability
High
Published: October 27, 2021 (1775 days ago)
Last Modified: August 11, 2026
Vendor: Cisco
Source: NVD

Description

A vulnerability in the Internet Key Exchange Version 2 (IKEv2) implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to trigger a denial of service (DoS) condition on an affected device. This vulnerability is due to improper control of a resource. An attacker with the ability to spoof a trusted IKEv2 site-to-site VPN peer and in possession of valid IKEv2 credentials for that peer could exploit this vulnerability by sending malformed, authenticated IKEv2 messages to an affected device. A successful exploit could allow the attacker to trigger a reload of the device.

CWE

CWE-416

Affected Products

cisco secure firewall threat defensecisco adaptive security appliance softwarecisco asa 5512-x firmwarecisco asa 5505 firmwarecisco asa 5515-x firmwarecisco asa 5525-x firmwarecisco asa 5545-x firmwarecisco asa 5555-x firmwarecisco asa 5580 firmwarecisco asa 5585-x firmware

References