CVE-2015-4550
published 2015-06-17CVE-2015-4550: The Cavium cryptographic-module firmware on Cisco Adaptive Security Appliance (ASA) devices with software 9.3(3) and 9.4(1.1) does not verify the AES-GCM…
PriorityP422medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.29%
67.0th percentile
The Cavium cryptographic-module firmware on Cisco Adaptive Security Appliance (ASA) devices with software 9.3(3) and 9.4(1.1) does not verify the AES-GCM Integrity Check Value (ICV) octets, which makes it easier for man-in-the-middle attackers to spoof IPSec and IKEv2 traffic by modifying packet data, aka Bug ID CSCuu66218.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Adaptive Security Appliance Encrypted IPSec or IKEv2 Packet Modification Vulnerability
vendor_cisco·2015-06-16·CVSS 4.3
CVE-2015-4550 [MEDIUM] Cisco Adaptive Security Appliance Encrypted IPSec or IKEv2 Packet Modification Vulnerability
Cisco Adaptive Security Appliance Encrypted IPSec or IKEv2 Packet Modification Vulnerability
A vulnerability in the AES-GCM code of Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to modify the contents of an encrypted IPSec or IKEv2 packet, and for those modifications not to be detected.
The vulnerability is due to an error on the firmware of the Cavium Networks cryptographic module. Due to this vulnerability, the integrity check value (ICV) is not verified. An attacker could exploit this vulnerability by intercepting encrypted packets in transit and modifying their contents. Such packets would be decrypted by the ASA and then forwarded to their destination, without the modification being detected.
Cisco has confirmed the vulnerability and releas
GHSA
GHSA-w7cf-c9rf-hghr: The Cavium cryptographic-module firmware on Cisco Adaptive Security Appliance (ASA) devices with software 9
ghsa_unreviewed·2022-05-17
CVE-2015-4550 [MEDIUM] GHSA-w7cf-c9rf-hghr: The Cavium cryptographic-module firmware on Cisco Adaptive Security Appliance (ASA) devices with software 9
The Cavium cryptographic-module firmware on Cisco Adaptive Security Appliance (ASA) devices with software 9.3(3) and 9.4(1.1) does not verify the AES-GCM Integrity Check Value (ICV) octets, which makes it easier for man-in-the-middle attackers to spoof IPSec and IKEv2 traffic by modifying packet data, aka Bug ID CSCuu66218.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-06-17
Published