5
CVSSv2

CVE-2013-1194

Published: 18/04/2013 Updated: 11/08/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The ISAKMP implementation on Cisco Adaptive Security Appliances (ASA) devices generates different responses for IKE aggressive-mode messages depending on whether invalid VPN groups are specified, which allows remote malicious users to enumerate groups via a series of messages, aka Bug ID CSCue73708.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco adaptive_security_appliance_software -

cisco adaptive_security_appliance

Vendor Advisories

A vulnerability in the Internet Security Association and Key Management Protocol (ISAKMP) implementation in Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to enumerate remote access VPN groups configured in a Cisco ASA device The vulnerability is due to differences in the way Cisco ASA Software re ...

Exploits

Cisco ASA versions 84(2), 84(5), and 91(1) suffer from a group name enumeration vulnerability in their IKE implementation ...