Cisco IOS XE IKEv1 Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in the Internet Key Exchange version 1 (IKEv1) implementation of Cisco IOS XE Software. This issue allows an authenticated, remote attacker with valid IKEv1 VPN credentials to cause a DoS condition by sending crafted IKEv1 messages. The vulnerability arises from improper validation of IKEv1 phase 2 parameters before the IPsec security association creation request is processed by the hardware cryptographic accelerator. Exploitation of this vulnerability can lead to the affected device reloading.

Impact

Exploitation of this vulnerability causes the affected device to reload, disrupting any active connections and services.

Remediation

Cisco has released free software updates to address this vulnerability. Customers with service contracts should obtain these updates through their usual channels. For those without service contracts, upgrades can be requested from the Cisco Technical Assistance Center (TAC).

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
8.1
impact
2.5
exploitability
4.9
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.