Cisco Secure Firewall Adaptive Security Appliance および Secure Firewall Threat Defense Software IKEv2 証明書認証サービス拒否の脆弱性
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software および Cisco Secure Firewall Threat Defense (FTD) Software の Internet Key Exchange version 2 (IKEv2) の証明書認証機能における脆弱性により、認証されていないリモートの攻撃者が影響を受けるデバイスを予期せず再ロードさせる可能性があります。この脆弱性は、IKEv2 接続セットアップの証明書認証フェーズ中のロジックエラーに起因します。攻撃者は、細工された証明書を使用して IKEv2 VPN 接続を確立しようとすることで、この脆弱性を悪用する可能性があります。悪用に成功すると、攻撃者は IKEv2 プロセスをクラッシュさせ、サービス拒否 (DoS) 状態を引き起こす可能性があります。Cisco は、この脆弱性に対処するソフトウェアアップデートをリリースしました。この脆弱性に対処する回避策はありません。このアドバイザリは、次のリンクで入手できます: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ikev2cert-dos-uWyc2xtvこのアドバイザリは、一連のアドバイザリの一部です。アドバイザリの完全なリストとそれらへのリンクについては、Cisco Advance Notification for Publication of September 16, 2026, Security Advisories を参照してください。さらに、Cisco Secure Firewall 製品の改善と修正に関する詳細なドキュメントについては、Cisco Secure Firewall Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, and Secure Firewall Management Center Software Hardening Release: September 2026 を参照してください。セキュリティ影響度評価: 高CVE: CVE-2026-20249