<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Thank you Marvin. Just an FYI in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/vulnerabilities-with-asa-service-module/m-p/2728793#M415705</link>
    <description>&lt;P&gt;Thank you Marvin.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just an FYI.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: &amp;quot;Calibri&amp;quot;,sans-serif; font-size: 11pt; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;"&gt;&lt;FONT color="#000000"&gt;The vulnerability says “if at least one DNS server IP address is configured under a DNS server group"&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: &amp;quot;Calibri&amp;quot;,sans-serif; font-size: 11pt; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;"&gt;&lt;FONT color="#000000"&gt;We only have domain-name configured but not a name-server so we're good.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 27 Oct 2015 16:29:55 GMT</pubDate>
    <dc:creator>aespanola</dc:creator>
    <dc:date>2015-10-27T16:29:55Z</dc:date>
    <item>
      <title>Vulnerabilities with ASA Service Module</title>
      <link>https://community.cisco.com/t5/network-security/vulnerabilities-with-asa-service-module/m-p/2728791#M415699</link>
      <description>&lt;P&gt;Cisco just recently releases security updates for ASA due to&amp;nbsp;number of vulnerabilities (See below). We don't provide any DNS, DHCP or VPN services in our ASA but our software image is listed as affected. Do we really need to upgrade the code? How can we check if&amp;nbsp; DNS, DHCP and IKE features are enabled or if they're running in ASA? Command 'show version' doesn't display it. Please advise.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;/Arnel&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;B&gt;&lt;SPAN style="font-size: 14.5pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;"&gt;&lt;A href="https://www.us-cert.gov/ncas/current-activity/2015/10/21/Cisco-Releases-Security-Updates" target="_blank"&gt;&lt;U&gt;&lt;FONT color="#0000ff" face="Times New Roman"&gt;Cisco Releases Security Updates&lt;/FONT&gt;&lt;/U&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;I&gt;&lt;SPAN style="color: rgb(102, 102, 102); font-size: 11pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;"&gt;&lt;FONT face="Times New Roman"&gt;10/21/2015 06:43 PM EDT&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;"&gt;&lt;FONT color="#000000" face="Times New Roman"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;"&gt;&lt;FONT color="#000000" face="Times New Roman"&gt;Original release date: October 21, 2015&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000" face="Times New Roman"&gt;Cisco has released updates to address multiple vulnerabilities in its Adaptive Security Appliance (ASA) software. Exploitation of these vulnerabilities could allow a remote attacker to cause a denial-of-service condition.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000" face="Times New Roman"&gt;US-CERT encourages users and administrators to review the Cisco security advisories on the &lt;/FONT&gt;&lt;A href="http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151021-asa-dns1" target="_blank"&gt;&lt;U&gt;&lt;FONT color="#0000ff" face="Times New Roman"&gt;ASA DNS Vulnerability 1&lt;/FONT&gt;&lt;/U&gt;&lt;/A&gt;&lt;FONT color="#000000" face="Times New Roman"&gt;, &lt;/FONT&gt;&lt;A href="http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151021-asa-dns2" target="_blank"&gt;&lt;U&gt;&lt;FONT color="#0000ff" face="Times New Roman"&gt;ASA DNS Vulnerability 2&lt;/FONT&gt;&lt;/U&gt;&lt;/A&gt;&lt;FONT color="#000000" face="Times New Roman"&gt;, &lt;/FONT&gt;&lt;A href="http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151021-asa-dhcp1" target="_blank"&gt;&lt;U&gt;&lt;FONT color="#0000ff" face="Times New Roman"&gt;ASA DHCP Vulnerability&lt;/FONT&gt;&lt;/U&gt;&lt;/A&gt;&lt;FONT color="#000000" face="Times New Roman"&gt;, and &lt;/FONT&gt;&lt;A href="http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151021-asa-ike" target="_blank"&gt;&lt;U&gt;&lt;FONT color="#0000ff" face="Times New Roman"&gt;ASA IKE Vulnerability&lt;/FONT&gt;&lt;/U&gt;&lt;/A&gt;&lt;FONT color="#000000" face="Times New Roman"&gt; and apply the necessary updates.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR align="center" size="2" width="100%" /&gt;</description>
      <pubDate>Fri, 21 Feb 2020 13:36:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vulnerabilities-with-asa-service-module/m-p/2728791#M415699</guid>
      <dc:creator>aespanola</dc:creator>
      <dc:date>2020-02-21T13:36:20Z</dc:date>
    </item>
    <item>
      <title>Your running configuration</title>
      <link>https://community.cisco.com/t5/network-security/vulnerabilities-with-asa-service-module/m-p/2728792#M415702</link>
      <description>&lt;P&gt;Your running configuration will tell you whether you are using any of the affected features.&lt;/P&gt;
&lt;P&gt;DNS and DHCP can be found with:&lt;/P&gt;

&lt;PRE&gt;
show run | i dns

show run | i dhcp&lt;/PRE&gt;

&lt;P&gt;IKEv1 is a little less straightforward as there are some IKE commands even in the factory default configuration, although they may not be used in many setups. Just inspect the configuration to see whether there are any site-site or remote access IPsec VPNs setup.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Oct 2015 03:20:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vulnerabilities-with-asa-service-module/m-p/2728792#M415702</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2015-10-23T03:20:08Z</dc:date>
    </item>
    <item>
      <title>Thank you Marvin. Just an FYI</title>
      <link>https://community.cisco.com/t5/network-security/vulnerabilities-with-asa-service-module/m-p/2728793#M415705</link>
      <description>&lt;P&gt;Thank you Marvin.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just an FYI.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: &amp;quot;Calibri&amp;quot;,sans-serif; font-size: 11pt; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;"&gt;&lt;FONT color="#000000"&gt;The vulnerability says “if at least one DNS server IP address is configured under a DNS server group"&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: &amp;quot;Calibri&amp;quot;,sans-serif; font-size: 11pt; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;"&gt;&lt;FONT color="#000000"&gt;We only have domain-name configured but not a name-server so we're good.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Oct 2015 16:29:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vulnerabilities-with-asa-service-module/m-p/2728793#M415705</guid>
      <dc:creator>aespanola</dc:creator>
      <dc:date>2015-10-27T16:29:55Z</dc:date>
    </item>
  </channel>
</rss>

