The IKE implementation in Cisco IOS 15.4(1)T and earlier and IOS XE allows remote attackers to cause a denial of service (security-association drop) via crafted Main Mode packets, aka Bug ID CSCun31021.
http://tools.cisco.com/security/center/viewAlert.x?alertId=33639
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-2143