CVE-2015-4458
published 2015-07-18CVE-2015-4458: The TLS implementation in the Cavium cryptographic-module firmware, as distributed with Cisco Adaptive Security Appliance (ASA) Software 9.1(5.21) and other…
PriorityP419medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
0.98%
58.3th percentile
The TLS implementation in the Cavium cryptographic-module firmware, as distributed with Cisco Adaptive Security Appliance (ASA) Software 9.1(5.21) and other products, does not verify the MAC field, which allows man-in-the-middle attackers to spoof TLS content by modifying packets, aka Bug ID CSCuu52976.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | adaptive_security_appliance_software | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Adaptive Security Appliance Message Authentication Code Checking Vulnerability
vendor_cisco·2015-07-14·CVSS 4.3
CVE-2015-4458 [MEDIUM] CWE-310 Cisco Adaptive Security Appliance Message Authentication Code Checking Vulnerability
Cisco Adaptive Security Appliance Message Authentication Code Checking Vulnerability
A vulnerability in the Transport Layer Security (TLS) code on the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to modify the contents of an encrypted TLS packet without detection of the modifications.
The vulnerability is due to an error on the firmware of the Cavium Networks cryptographic module. Due to this vulnerability, the message authentication code (MAC) on a TLS packet is not being checked. An attacker could exploit this vulnerability by intercepting encrypted packets in transit and modifying their contents. Such packets would be decrypted by the ASA, but the modification would not be detected.
Cisco has confirmed the vulnerability and released software
GHSA
GHSA-3479-67mc-93x4: The TLS implementation in the Cavium cryptographic-module firmware, as distributed with Cisco Adaptive Security Appliance (ASA) Software 9
ghsa_unreviewed·2022-05-17
CVE-2015-4458 [MEDIUM] GHSA-3479-67mc-93x4: The TLS implementation in the Cavium cryptographic-module firmware, as distributed with Cisco Adaptive Security Appliance (ASA) Software 9
The TLS implementation in the Cavium cryptographic-module firmware, as distributed with Cisco Adaptive Security Appliance (ASA) Software 9.1(5.21) and other products, does not verify the MAC field, which allows man-in-the-middle attackers to spoof TLS content by modifying packets, aka Bug ID CSCuu52976.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-07-18
Published