Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w7cf-c9rf-hghr

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Cavium cryptographic-module firmware on Cisco Adaptive Security Appliance (ASA) devices with software 9.3(3) and 9.4(1.1) does not verify the AES-GCM Integrity Check Value (ICV) octets, which makes it easier for man-in-the-middle attackers to spoof IPSec and IKEv2 traffic by modifying packet data, aka Bug ID CSCuu66218.

The Cavium cryptographic-module firmware on Cisco Adaptive Security Appliance (ASA) devices with software 9.3(3) and 9.4(1.1) does not verify the AES-GCM Integrity Check Value (ICV) octets, which makes it easier for man-in-the-middle attackers to spoof IPSec and IKEv2 traffic by modifying packet data, aka Bug ID CSCuu66218.

EPSS

Процентиль: 65%
0.00501
Низкий

Связанные уязвимости

nvd
больше 10 лет назад

The Cavium cryptographic-module firmware on Cisco Adaptive Security Appliance (ASA) devices with software 9.3(3) and 9.4(1.1) does not verify the AES-GCM Integrity Check Value (ICV) octets, which makes it easier for man-in-the-middle attackers to spoof IPSec and IKEv2 traffic by modifying packet data, aka Bug ID CSCuu66218.

fstec
больше 10 лет назад

Уязвимость межсетевого экрана Cisco ASA, позволяющая нарушителю получить доступ к трафику, передаваемому по протоколам IPSec и IKEv2

EPSS

Процентиль: 65%
0.00501
Низкий