CVE-2015-4458Cisco Adaptive Security Appliance Software vulnerability

CWE-3104 documents4 sources
Severity
4.3MEDIUMNVD
EPSS
0.4%
top 36.61%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 18
Latest updateMay 17

Description

The TLS implementation in the Cavium cryptographic-module firmware, as distributed with Cisco Adaptive Security Appliance (ASA) Software 9.1(5.21) and other products, does not verify the MAC field, which allows man-in-the-middle attackers to spoof TLS content by modifying packets, aka Bug ID CSCuu52976.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-3479-67mc-93x4: The TLS implementation in the Cavium cryptographic-module firmware, as distributed with Cisco Adaptive Security Appliance (ASA) Software 92022-05-17
CVEList
CVE-2015-4458: The TLS implementation in the Cavium cryptographic-module firmware, as distributed with Cisco Adaptive Security Appliance (ASA) Software 92015-07-18

📋Vendor Advisories

1
Cisco
Cisco Adaptive Security Appliance Message Authentication Code Checking Vulnerability2015-07-14
CVE-2015-4458 — Cisco vulnerability | cvebase