Lucene search

K
ciscoCiscoCISCO-SA-20160927-OPENSSL
HistorySep 27, 2016 - 10:40 p.m.

Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016

2016-09-2722:40:00
tools.cisco.com
242

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

8.2 High

AI Score

Confidence

Low

0.911 High

EPSS

Percentile

98.9%

On September 22, 2016, the OpenSSL Software Foundation released an advisory that describes 14 vulnerabilities. Of these 14 vulnerabilities, the OpenSSL Software Foundation classifies one as “Critical Severity,” one as “Moderate Severity,” and the other 12 as “Low Severity.”

Subsequently, on September 26, the OpenSSL Software Foundation released an additional advisory that describes two new vulnerabilities. These vulnerabilities affect the OpenSSL versions that were released to address the vulnerabilities disclosed in the previous advisory. One of the new vulnerabilities was rated as “High Severity” and the other as “Moderate Severity.”

Of the 16 released vulnerabilities:

Fourteen track issues that could result in a denial of service (DoS) condition
One (CVE-2016-2183, aka SWEET32) tracks an implementation of a Birthday attack against Transport Layer Security (TLS) block ciphers that use a 64-bit block size that could result in loss of confidentiality
One (CVE-2016-2178) is a timing side-channel attack that, in specific circumstances, could allow an attacker to derive the private DSA key that belongs to another user or service running on the same system
Five of the 16 vulnerabilities exclusively affect the recently released OpenSSL versions that are part of the 1.1.0 release series, which has not yet been integrated into any Cisco product.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160927-openssl [“https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160927-openssl”]

Affected configurations

Vulners
Node
ciscoapplication_and_content_networking_system_softwareMatchany
OR
ciscoprime_access_registrarMatchany
OR
ciscoemergency_responderMatchany
OR
ciscounified_contact_center_expressMatchany
OR
ciscoios_xr_softwareMatchany
OR
ciscocisco_ons_15454_system_softwareMatchany
OR
ciscounity_expressMatchany
OR
cisconac_guest_server_softwareMatchany
OR
ciscointrusion_prevention_systemMatchany
OR
ciscoadaptive_security_virtual_applianceMatchany
OR
ciscoace_application_control_engine_module_a1Matchany
OR
ciscowide_area_application_servicesMatchany
OR
ciscowireless_lan_controller_6.0Matchany
OR
ciscounified_contact_center_enterpriseMatchany
OR
ciscounified_meetingplaceMatchany
OR
ciscoip_interoperability_and_collaboration_systemMatchany
OR
ciscounity_connectionMatchany
OR
ciscotelepresence_managerMatchany
OR
ciscosecurity_managerMatchany
OR
ciscoace_application_control_engine_module_a1Matchany
OR
ciscounified_contact_center_expressMatchany
OR
ciscorvs4000_softwareMatchany
OR
ciscovideo_surveillance_media_serverMatchany
OR
ciscodigital_media_managerMatchany
OR
ciscodigital_media_managerMatchany
OR
ciscoprime_network_analysis_module_softwareMatchany
OR
ciscowebex_event_centerMatchany
OR
ciscowebex_meeting_centerMatchany
OR
ciscowebex_support_centerMatchany
OR
ciscowebex_training_centerMatchany
OR
cisconetwork_admission_controlMatchany
OR
ciscoanyconnect_secure_mobility_clientMatchany
OR
ciscoshow_and_shareMatchany
OR
ciscomobility_services_engineMatchany
OR
ciscoidentity_services_engine_softwareMatchany
OR
ciscotelepresence_video_communication_server_softwareMatchany
OR
ciscoprime_data_center_network_managerMatchany
OR
ciscosmall_business_220_series_smart_plus_switchesMatchany
OR
ciscosmall_business_220_series_smart_plus_switchesMatchany
OR
ciscoata_187_analog_telephone_adaptorMatchany
OR
ciscoprime_lan_management_solutionMatchany
OR
ciscounified_communications_domain_managerMatchany
OR
ciscoemail_security_virtual_applianceMatchany
OR
ciscocontent_security_management_virtual_applianceMatchany
OR
ciscoprime_infrastructureMatchany
OR
ciscoconnected_grid_network_management_systemMatchany
OR
ciscojabber_imMatchanyandroid
OR
ciscowebex_meetings_serverMatchany
OR
ciscowebex_node_for_mcsMatchany
OR
ciscounified_computing_system_central_softwareMatchany
OR
ciscojabberMatchanywindows
OR
ciscoenterprise_content_delivery_systemMatchany
OR
ciscoasr_5000_series_softwareMatchany
OR
ciscounified_ip_phone_8945Matchany
OR
ciscosocialminerMatchany
OR
ciscomediasenseMatchany
OR
ciscotelepresence_managerMatchany
OR
ciscovideo_surveillance_ip_gateway_encoder_decoderMatchany
OR
ciscounified_sip_proxyMatchany
OR
ciscovirtualization_experience_media_engineMatchany
OR
ciscocisco_nexus_1000v_intercloudMatchanyvmware
OR
ciscoprime_network_registrarMatchany
OR
ciscoucs_directorMatchany
OR
ciscodigital_content_managerMatchany
OR
ciscounified_intelligence_centerMatchany
OR
ciscocisco_nexus_1000v_intercloudMatchanyvmware
OR
ciscoexpresswayMatchany
OR
ciscoprime_opticalMatchany
OR
ciscojabber_guestMatchany
OR
ciscodesktop_collaboration_experienceMatchany
OR
ciscotelepresence_serial_gatewayMatchany
OR
ciscoprime_license_managerMatchany
OR
ciscoprime_collaboration_deploymentMatchany
OR
ciscoacs_for_windowsMatchany
OR
ciscoip_contact_center_expressMatchany
OR
ciscovirtual_topology_systemMatchany
OR
ciscoprime_network_services_controllerMatchany
OR
ciscotelepresence_isdn_gateway_softwareMatchany
OR
ciscotelepresence_conductorMatchany
OR
ciscounified_workforce_optimizationMatchanysr7
OR
ciscovideo_surveillance_ip_gateway_encoder_decoderMatchany
OR
ciscovideo_surveillance_ip_gateway_encoder_decoderMatchany
OR
ciscovideo_surveillance_ip_gateway_encoder_decoderMatchany
OR
ciscovideo_surveillance_ip_gateway_encoder_decoderMatchany
OR
ciscowebex_meetingsMatchanyandroid
OR
ciscowebex_meetingsMatchanywindows
OR
ciscofirepower_system_softwareMatchany
OR
ciscoip_phone_8800_seriesMatchany
OR
ciscoucs_b-series_blade_server_softwareMatchany
OR
ciscoprime_collaboration_assuranceMatchany
OR
ciscoprime_collaboration_provisioningMatchany
OR
ciscojabber_software_development_kitMatchany
OR
ciscojabberMatchanymac
OR
ciscojabberMatchany
OR
ciscoapplication_policy_infrastructure_controllerMatchanyc
OR
ciscopacket_tracerMatchany
OR
ciscoprime_networkMatchany
OR
ciscoprime_security_managerMatchany
OR
ciscoagent_desktopMatchany
OR
ciscoip_phone_8800_seriesMatchany
OR
ciscopaging_serverMatchany
OR
ciscocisco_spa112Matchany
OR
ciscoataMatchany
OR
ciscoataMatchany
OR
ciscounified_attendant_console_advancedMatchany
OR
ciscovideoscape_distribution_suite_optimization_engineMatchany
OR
ciscoip_phone_8800_seriesMatchany
OR
ciscoip_phone_8800_seriesMatchany
OR
cisconx-osMatchanynexus_9000_series
OR
ciscocisco_policy_suiteMatchany
OR
ciscosmall_business_220_series_smart_plus_switchesMatchany
OR
ciscohosted_collaboration_mediation_fulfillmentMatchany
OR
ciscoregistered_envelope_serviceMatchany
OR
ciscoapplication_and_content_networking_system_softwareMatchany
OR
ciscoprime_access_registrarMatchany
OR
ciscoemergency_responderMatchany
OR
ciscounified_contact_center_expressMatchany
OR
ciscoios_xr_softwareMatchany
OR
ciscoonsMatch15454_system_software
OR
ciscounity_expressMatchany
OR
cisconac_guest_server_softwareMatchany
OR
ciscointrusion_prevention_systemMatchany
OR
ciscoadaptive_security_virtual_applianceMatchany
OR
ciscoace_application_control_engine_module_a1Matchany
OR
ciscowide_area_application_servicesMatchany
OR
ciscowireless_lan_controller_6.0Matchany
OR
ciscounified_contact_center_enterpriseMatchany
OR
ciscounified_meetingplaceMatchany
OR
ciscoip_interoperability_and_collaboration_systemMatchany
OR
ciscounity_connectionMatchany
OR
ciscotelepresence_managerMatchany
OR
ciscosecurity_managerMatchany
OR
ciscoace_application_control_engine_module_a1Match4700_series_application_control_engine_appliances
OR
ciscounified_contact_center_expressMatchany
OR
ciscorvs4000_softwareMatchany
OR
ciscovideo_surveillance_media_serverMatchany
OR
ciscodigital_media_managerMatchany
OR
ciscodigital_media_managerMatchany
OR
ciscoprime_network_analysis_module_softwareMatchany
OR
ciscowebex_event_centerMatchany
OR
ciscowebex_meeting_centerMatchany
OR
ciscowebex_support_centerMatchany
OR
ciscowebex_training_centerMatchany
OR
cisconetwork_admission_controlMatchany
OR
ciscoanyconnect_secure_mobility_clientMatchany
OR
ciscoshow_and_shareMatchany
OR
ciscomobility_services_engineMatchany
OR
ciscoidentity_services_engine_softwareMatchany
OR
ciscotelepresence_video_communication_server_softwareMatchany
OR
ciscoprime_data_center_network_managerMatchany
OR
ciscosmall_business_srp520_series_firmwareMatch300_series_managed_switches
OR
ciscosmall_business_srp520_series_firmwareMatch500_series_stackable_managed_switches
OR
ciscoataMatch187_analog_telephone_adaptor
OR
ciscoprime_lan_management_solutionMatchany
OR
ciscounified_communications_domain_managerMatchany
OR
ciscoemail_security_virtual_applianceMatchany
OR
ciscocontent_security_management_virtual_applianceMatchany
OR
ciscoprime_infrastructureMatchany
OR
ciscoconnected_grid_network_management_systemMatchany
OR
ciscojabber_imMatchanyandroid
OR
ciscowebex_meetings_serverMatchany
OR
ciscowebex_node_for_mcsMatchany
OR
ciscounified_computing_system_central_softwareMatchany
OR
ciscojabberMatchanywindows
OR
ciscoenterprise_content_delivery_systemMatchany
OR
ciscoasr_5000_series_softwareMatch5000_series_software
OR
ciscounified_ip_phoneMatch8945
OR
ciscosocialminerMatchany
OR
ciscomediasenseMatchany
OR
ciscotelepresence_managerMatchany
OR
ciscovideo_surveillance_softwareMatch4000_series_ip_camera
OR
ciscounified_sip_proxyMatchany
OR
ciscocisco_mxeMatch3500_\(media_experience_engine\)
OR
cisconexus_insightsMatch1000v_intercloud_for_vmware
OR
ciscoprime_network_registrarMatchany
OR
ciscoucs_directorMatchany
OR
ciscodigital_content_managerMatchany
OR
ciscounified_intelligence_centerMatchany
OR
cisconexus_insightsMatch1000v_switch
OR
ciscoexpresswayMatchany
OR
ciscoprime_opticalMatchany
OR
ciscojabber_guestMatchany
OR
ciscodesktop_collaboration_experienceMatchany
OR
ciscotelepresence_serial_gatewayMatchany
OR
ciscoprime_license_managerMatchany
OR
ciscoprime_collaboration_deploymentMatchany
OR
ciscoacs_for_windowsMatchany
OR
ciscoip_contact_center_expressMatchany
OR
ciscovirtual_topology_systemMatchany
OR
ciscoprime_network_services_controllerMatchany
OR
ciscotelepresence_isdn_gateway_softwareMatchany
OR
ciscotelepresence_conductorMatchany
OR
ciscounified_workforce_optimizationMatchanysr7
OR
ciscovideo_surveillance_softwareMatch3000_series_ip_cameras
OR
ciscovideo_surveillance_softwareMatch6000_series_ip_cameras
OR
ciscovideo_surveillance_softwareMatch7000_series_ip_cameras
OR
ciscovideo_surveillance_ip_gateway_encoder_decoderMatchany
OR
ciscowebex_meetingsMatchanyandroid
OR
ciscowebex_meetingsMatch8windows
OR
ciscofirepower_system_softwareMatchany
OR
ciscoip_phone_8800_seriesMatch8800_series_software
OR
ciscoucs_b-series_blade_server_softwareMatchany
OR
ciscoprime_collaboration_assuranceMatchany
OR
ciscoprime_collaboration_provisioningMatchany
OR
ciscojabber_software_development_kitMatchany
OR
ciscojabberMatchanymac
OR
ciscojabberMatchany
OR
ciscoapplication_policy_infrastructure_controllerMatchanyc
OR
ciscopacket_tracerMatchany
OR
ciscoprime_networkMatchany
OR
ciscoprime_security_managerMatchany
OR
ciscoagent_desktopMatchany
OR
ciscoip_phone_8800_seriesMatchany
OR
ciscopaging_serverMatchany
OR
ciscocisco_spa112Match2-port_phone_adapter
OR
ciscoataMatchany
OR
ciscoataMatchany
OR
ciscounified_attendant_console_advancedMatchany
OR
ciscovideoscape_distribution_suite_optimization_engineMatchany
OR
ciscoip_phone_8800_seriesMatch7800_series
OR
ciscounified_ip_phoneMatch7900_series
OR
cisconexus_insightsMatch3000_series_switch
OR
ciscocisco_policy_suiteMatchany
OR
ciscosmall_business_srp520_series_firmwareMatch220_series_smart_plus_switches
OR
ciscohosted_collaboration_mediation_fulfillmentMatchany
OR
ciscoregistered_envelope_serviceMatchany

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

8.2 High

AI Score

Confidence

Low

0.911 High

EPSS

Percentile

98.9%