Lucene search

K
cveMitreCVE-2015-4550
HistoryJun 17, 2015 - 10:59 a.m.

CVE-2015-4550

2015-06-1710:59:07
CWE-310
mitre
web.nvd.nist.gov
32
cavium
cisco
asa
firmware
aes-gcm
icv
ipsec
ikev2
cve-2015-4550

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

6.8

Confidence

Low

EPSS

0.001

Percentile

23.6%

The Cavium cryptographic-module firmware on Cisco Adaptive Security Appliance (ASA) devices with software 9.3(3) and 9.4(1.1) does not verify the AES-GCM Integrity Check Value (ICV) octets, which makes it easier for man-in-the-middle attackers to spoof IPSec and IKEv2 traffic by modifying packet data, aka Bug ID CSCuu66218.

Affected configurations

Nvd
Node
ciscoadaptive_security_appliance_softwareMatch9.3\(3\)
OR
ciscoadaptive_security_appliance_softwareMatch9.4\(1.1\)
VendorProductVersionCPE
ciscoadaptive_security_appliance_software9.3(3)cpe:2.3:o:cisco:adaptive_security_appliance_software:9.3\(3\):*:*:*:*:*:*:*
ciscoadaptive_security_appliance_software9.4(1.1)cpe:2.3:o:cisco:adaptive_security_appliance_software:9.4\(1.1\):*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

6.8

Confidence

Low

EPSS

0.001

Percentile

23.6%

Related for CVE-2015-4550