VDB

GCVE-110-NCSC-2026-104

GCVE-110-NCSC-2026-104
Advisory PublishedCVSS 8.6/10
Vulnetix · Advisory published March 26, 2026
A vulnerability in the IKEv2 feature of multiple Cisco software products allows an unauthenticated remote attacker to cause a memory leak resulting in denial of service, necessitating a manual reboot to restore service.

Weaknesses (CWE)

CWE-401Missing Release of Memory after Effective LifetimeCWE-230Improper Handling of Missing ValuesCWE-771Missing Reference to Active Allocated ResourceCWE-319Cleartext Transmission of Sensitive InformationCWE-228Improper Handling of Syntactically Invalid StructureCWE-1286Improper Validation of Syntactic Correctness of InputCWE-266Incorrect Privilege AssignmentCWE-124Buffer Underwrite ('Buffer Underflow')CWE-235Improper Handling of Extra Parameters

Risk Scores

CVSS 3.1
8.6/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

Affected Products

VendorProductVersionsPlatforms
Ciscovers:unknown/*

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

73,877 records in the GCVE database · Updated July 20, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›