4.3
CVSSv2

CVE-2015-4550

Published: 17/06/2015 Updated: 11/08/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The Cavium cryptographic-module firmware on Cisco Adaptive Security Appliance (ASA) devices with software 9.3(3) and 9.4(1.1) does not verify the AES-GCM Integrity Check Value (ICV) octets, which makes it easier for man-in-the-middle malicious users to spoof IPSec and IKEv2 traffic by modifying packet data, aka Bug ID CSCuu66218.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco adaptive security appliance software 9.4\\(1.1\\)

cisco adaptive security appliance software 9.3\\(3\\)

Vendor Advisories

A vulnerability in the AES-GCM code of Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to modify the contents of an encrypted IPSec or IKEv2 packet, and for those modifications not to be detected The vulnerability is due to an error on the firmware of the Cavium Networks cryptographic module Due to this vu ...