Cisco ASA Uncontrolled Resource Consumption (CVE-2021-40125)

medium Tenable OT Security Plugin ID 506134

Synopsis

The remote OT asset is affected by a vulnerability.

Description

A vulnerability in the Internet Key Exchange Version 2 (IKEv2) implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to trigger a denial of service (DoS) condition on an affected device. This vulnerability is due to improper control of a resource. An attacker with the ability to spoof a trusted IKEv2 site-to-site VPN peer and in possession of valid IKEv2 credentials for that peer could exploit this vulnerability by sending malformed, authenticated IKEv2 messages to an affected device. A successful exploit could allow the attacker to trigger a reload of the device.

This plugin only works with Tenable.ot.
Please visit https://www.tenable.com/products/tenable-ot for more information.

Solution

Refer to the vendor advisory.

See Also

http://www.nessus.org/u?0c784582

Plugin Details

Severity: Medium

ID: 506134

File Name: tenable_ot_cisco_CVE-2021-40125.nasl

Version: 1.1

Type: Remote

Family: Tenable.ot

Published: 10/6/2026

Updated: 10/6/2026

Supported Sensors: Tenable OT Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.18

CVSS v2

Risk Factor: Medium

Base Score: 6.3

Vector: CVSS2#AV:N/AC:M/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2021-40125

CVSS v3

Risk Factor: Medium

Base Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Vulnerability Information

CPE: cpe:/o:cisco:adaptive_security_appliance_software:9

Required KB Items: Tenable.ot/Cisco

Patch Publication Date: 10/27/2021

Vulnerability Publication Date: 10/27/2021

Reference Information

CVE: CVE-2021-40125

CWE: 400, 416