<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>tema Outdated OpenSSL package - does ASA have Open SSL ? en Network Security</title>
    <link>https://community.cisco.com/t5/network-security/outdated-openssl-package-does-asa-have-open-ssl/m-p/2138949#M359809</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Marcin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for the response.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is the vulnerability: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"An outdated OpenSSL package was identified that was vulnerable to a heap corruption bug that may be exploited by an attacker to acquire command execution on the host, or to create denial of service conditions."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;They suggest we do the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Update the outdated /&amp;nbsp;&amp;nbsp; vulnerable OpenSSL package to the latest stable version"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Zubair&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 20 Mar 2013 13:32:15 GMT</pubDate>
    <dc:creator>Zubair.Sayed_2</dc:creator>
    <dc:date>2013-03-20T13:32:15Z</dc:date>
    <item>
      <title>Outdated OpenSSL package - does ASA have Open SSL ?</title>
      <link>https://community.cisco.com/t5/network-security/outdated-openssl-package-does-asa-have-open-ssl/m-p/2138947#M359807</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On one of our firewalls we hosting a application/service which impacts clients and we recently conducted a Pen test, the external company doing the Pen test have advised us that there is a vulnerability relating to OpenSSL. We have checked the server and there is no OpenSSL installed so the only place where it could be picking this up is on the ASA, is this correct?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;Here is the report from the company that conducted the test:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;4.3 Network Security &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;An outdated OpenSSL package was identified that was vulnerable to a heap corruption bug that may be exploited by an attacker to acquire command execution on the host, or to create denial of service conditions. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE border="0" cellpadding="0" cellspacing="0" style="margin-left: -5.4pt; border-collapse: collapse; padding: px;"&gt;&lt;TBODY&gt;&lt;TR style="height: 3.75pt;"&gt;&lt;TD style="padding: 0cm 5.4pt 0cm 5.4pt; height: 3.75pt;" valign="top"&gt;&lt;P&gt;Table 7&amp;nbsp;&amp;nbsp; provides an overview of the risk identified per network assessment category,&amp;nbsp;&amp;nbsp; along with recommendations for resolving the issues identified. &lt;STRONG&gt;Category &lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="padding: 0cm 5.4pt 0cm 5.4pt; height: 3.75pt;" valign="top"&gt;&lt;P&gt;&lt;STRONG&gt;Risk &lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="padding: 0cm 5.4pt 0cm 5.4pt; height: 3.75pt;" valign="top"&gt;&lt;P&gt;&lt;STRONG&gt;Summary &lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="padding: 0cm 5.4pt 0cm 5.4pt; height: 3.75pt;" valign="top"&gt;&lt;P&gt;&lt;STRONG&gt;Recommendations &lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="height: 14.7pt;"&gt;&lt;TD style="padding: 0cm 5.4pt 0cm 5.4pt; height: 14.7pt;" valign="top"&gt;&lt;P&gt;Patch Management &lt;/P&gt;&lt;/TD&gt;&lt;TD style="padding: 0cm 5.4pt 0cm 5.4pt; height: 14.7pt;" valign="top"&gt;&lt;P&gt;&lt;STRONG&gt;High &lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="padding: 0cm 5.4pt 0cm 5.4pt; height: 14.7pt;" valign="top"&gt;&lt;P&gt;The OpenSSL package installed&amp;nbsp;&amp;nbsp; on one host was identified as being outdated and subject to a heap corruption&amp;nbsp;&amp;nbsp; bug. &lt;/P&gt;&lt;/TD&gt;&lt;TD style="padding: 0cm 5.4pt 0cm 5.4pt; height: 14.7pt;" valign="top"&gt;&lt;P&gt;Update the outdated /&amp;nbsp;&amp;nbsp; vulnerable OpenSSL package to the latest stable version. &lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;We have an ASA5520 and running the following version:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco Adaptive Security Appliance Software Version &lt;STRONG&gt;8.2(5)2&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How do we check the OpenSSL on the ASA and secondly do we need to update the ASA software version ???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Zubair&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:16:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/outdated-openssl-package-does-asa-have-open-ssl/m-p/2138947#M359807</guid>
      <dc:creator>Zubair.Sayed_2</dc:creator>
      <dc:date>2019-03-12T01:16:47Z</dc:date>
    </item>
    <item>
      <title>Outdated OpenSSL package - does ASA have Open SSL ?</title>
      <link>https://community.cisco.com/t5/network-security/outdated-openssl-package-does-asa-have-open-ssl/m-p/2138948#M359808</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Zubair, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes we use parts of openssl. As mentioned in opensource/free license information. &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa82/license/opensrce.html#wp71205"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/license/opensrce.html#wp71205&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the specific vulnarability that was found? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;M. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Mar 2013 13:28:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/outdated-openssl-package-does-asa-have-open-ssl/m-p/2138948#M359808</guid>
      <dc:creator>Marcin Latosiewicz</dc:creator>
      <dc:date>2013-03-20T13:28:25Z</dc:date>
    </item>
    <item>
      <title>Outdated OpenSSL package - does ASA have Open SSL ?</title>
      <link>https://community.cisco.com/t5/network-security/outdated-openssl-package-does-asa-have-open-ssl/m-p/2138949#M359809</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Marcin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for the response.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is the vulnerability: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"An outdated OpenSSL package was identified that was vulnerable to a heap corruption bug that may be exploited by an attacker to acquire command execution on the host, or to create denial of service conditions."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;They suggest we do the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Update the outdated /&amp;nbsp;&amp;nbsp; vulnerable OpenSSL package to the latest stable version"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Zubair&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Mar 2013 13:32:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/outdated-openssl-package-does-asa-have-open-ssl/m-p/2138949#M359809</guid>
      <dc:creator>Zubair.Sayed_2</dc:creator>
      <dc:date>2013-03-20T13:32:15Z</dc:date>
    </item>
    <item>
      <title>Outdated OpenSSL package - does ASA have Open SSL ?</title>
      <link>https://community.cisco.com/t5/network-security/outdated-openssl-package-does-asa-have-open-ssl/m-p/2138950#M359810</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Zubair, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We need to know &lt;SPAN style="font-size: 10pt;"&gt;CVE (like &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;CVE-2012-4659 )&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt; , this is how you can check whether ASA is affected. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Our PSIRT (cisco.com/go/psirt) is publishing advisories and mentiones CVE (typically).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;So you can find, for example: &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20121010-asa"&gt;http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20121010-asa&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;M.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Mar 2013 13:47:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/outdated-openssl-package-does-asa-have-open-ssl/m-p/2138950#M359810</guid>
      <dc:creator>Marcin Latosiewicz</dc:creator>
      <dc:date>2013-03-20T13:47:57Z</dc:date>
    </item>
    <item>
      <title>Hello, I am receiving a</title>
      <link>https://community.cisco.com/t5/network-security/outdated-openssl-package-does-asa-have-open-ssl/m-p/2138951#M359811</link>
      <description>&lt;P&gt;Hello, I am receiving a similar error for ASA 8.2.3. The Open Source license linked above only shows that the license exists, not the version of OpenSSL that goes with a given ASA version. The vulnerability is related to&amp;nbsp;CVE-2008-7270, which apparently is not referenced in the PSIRT database and only as part of a bunch of other alerts. Is there an ASA command to derive the OpenSSL version in use?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Pete&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jan 2015 18:26:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/outdated-openssl-package-does-asa-have-open-ssl/m-p/2138951#M359811</guid>
      <dc:creator>peter.hewitt1</dc:creator>
      <dc:date>2015-01-07T18:26:50Z</dc:date>
    </item>
    <item>
      <title>Pete,  I don't believe we</title>
      <link>https://community.cisco.com/t5/network-security/outdated-openssl-package-does-asa-have-open-ssl/m-p/2138952#M359812</link>
      <description>&lt;P&gt;Pete,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't believe we publish anything outside except version 1.0/0.9 etc.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For your particular vulnerability have a look at:&lt;/P&gt;&lt;P&gt;https://tools.cisco.com/bugsearch/bug/CSCtk61443/?referring_site=bugqvinvisibleredir&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is fixed in 8.2.5 and newer.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;M.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jan 2015 18:55:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/outdated-openssl-package-does-asa-have-open-ssl/m-p/2138952#M359812</guid>
      <dc:creator>Marcin Latosiewicz</dc:creator>
      <dc:date>2015-01-07T18:55:56Z</dc:date>
    </item>
    <item>
      <title>That helps a great deal, we</title>
      <link>https://community.cisco.com/t5/network-security/outdated-openssl-package-does-asa-have-open-ssl/m-p/2138953#M359813</link>
      <description>&lt;P&gt;That helps a great deal, we're going to do the 8.2.5 upgrade this week. Thanks for your reply!&lt;/P&gt;&lt;P&gt;- Pete&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jan 2015 19:16:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/outdated-openssl-package-does-asa-have-open-ssl/m-p/2138953#M359813</guid>
      <dc:creator>peter.hewitt1</dc:creator>
      <dc:date>2015-01-07T19:16:08Z</dc:date>
    </item>
  </channel>
</rss>

