CNNVD-202508-1694 Information

CNNVD ID

CNNVD-202508-1694

CVE-2025-20225

  • CNNVD Published: 2025-08-14

Description (Chinese)

Cisco IOS等都是美国思科(Cisco)公司的产品。Cisco IOS是一套为其网络设备开发的操作系统。Cisco Adaptive Security Appliances Software(ASA Software)是一套防火墙和网络安全平台。Cisco IOS XE是一个操作系统。 Cisco多款产品存在安全漏洞,该漏洞源于IKEv2数据包处理不当,可能导致内存泄漏和拒绝服务攻击。以下产品受到影响:Cisco IOS、IOS XE、Adaptive Security Appliance Software和Secure Firewall Threat Defense Software。

Description (English)

Cisco IOS and others are all Cisco products. Cisco IOS is an operating system developed for its network equipment. Cisco Adaptive Security Applications Software (ASA Software) is a firewall and network security platform. Cisco IOS XE is an operating system. There is a safety gap in Cisco ’ s multiple products, which stems from the inappropriate handling of IKEv2 data packages, which could lead to memory leakage and denial of service attacks. The following products were affected: Cisco IOS, IOS XE, Adamtive Security Application Software and Secure Fairewall Threat Defense Software.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

思科

Published

2025-08-14

Last Modified

2026-02-24

References

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asa-ftd-ios-dos-DOESHWHy https://nvd.nist.gov/vuln/detail/CVE-2025-20225

Patch

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asa-ftd-ios-dos-DOESHWHy

Share on: