ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Cisco ASA vulterablities

    IT Discussion
    3
    4
    846
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      Jason Banned
      last edited by Jason

      https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160210-asa-ike

      A vulnerability in the Internet Key Exchange (IKE) version 1 (v1) and IKE version 2 (v2) code of Cisco ASA Software could allow an unauthenticated, remote attacker to cause a reload of the affected system or to remotely execute code.

      The vulnerability is due to a buffer overflow in the affected code area. An attacker could exploit this vulnerability by sending crafted UDP packets to the affected system. An exploit could allow the attacker to execute arbitrary code and obtain full control of the system or to cause a reload of the affected system.

      1 Reply Last reply Reply Quote 4
      • DashrenderD
        Dashrender
        last edited by

        Thanks - I have one customer with one of these.. might be time to change to a ERL

        J 1 Reply Last reply Reply Quote 0
        • J
          Jason Banned @Dashrender
          last edited by Jason

          @Dashrender said:

          Thanks - I have one customer with one of these.. might be time to change to a ERL

          It's an easy upgrade Just upgrade to the ASA version not affected.

          dafyreD 1 Reply Last reply Reply Quote 1
          • dafyreD
            dafyre @Jason
            last edited by

            @Jason said:

            @Dashrender said:

            Thanks - I have one customer with one of these.. might be time to change to a ERL

            It's an easy upgrade Just upgrade to the ASA version not affected.

            Assuming said customer is paying the contortionist extortionist pricing for software updates.

            1 Reply Last reply Reply Quote 0
            • 1 / 1
            • First post
              Last post