<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic I am running 4.5.0, it is in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-security-manager-is-vulnerable-to-cve-2014-0160-aka/m-p/2474466#M921849</link>
    <description>&lt;P&gt;I am running 4.5.0, it is vulnerable because I have scanned it and tested it. I see version 4.6.0 has just popped up on cisco.com. Anyone confirm if that fixes the bug?&lt;/P&gt;</description>
    <pubDate>Wed, 16 Apr 2014 04:43:29 GMT</pubDate>
    <dc:creator>Network Operation</dc:creator>
    <dc:date>2014-04-16T04:43:29Z</dc:date>
    <item>
      <title>Cisco Security Manager is vulnerable to CVE-2014-0160 - aka Heartbleed</title>
      <link>https://community.cisco.com/t5/network-security/cisco-security-manager-is-vulnerable-to-cve-2014-0160-aka/m-p/2474463#M921844</link>
      <description>&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; We have CSM 4.4.0 SP2 patch 1 installed with no default configuration.&lt;/P&gt;&lt;P&gt;According to cisco, CSM is under&amp;nbsp;Vulnerable Products list with cisco bug ID&amp;nbsp;CSCuo19265.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do I need to take any action for my CSM ?&lt;/P&gt;&lt;P&gt;Thanks &amp;amp; Regards&lt;/P&gt;&lt;P&gt;Ahmed...&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 13:09:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-security-manager-is-vulnerable-to-cve-2014-0160-aka/m-p/2474463#M921844</guid>
      <dc:creator>ahmed.gadi</dc:creator>
      <dc:date>2020-02-21T13:09:38Z</dc:date>
    </item>
    <item>
      <title>I recommend that you restrict</title>
      <link>https://community.cisco.com/t5/network-security/cisco-security-manager-is-vulnerable-to-cve-2014-0160-aka/m-p/2474464#M921846</link>
      <description>&lt;P&gt;I recommend that you restrict HTTPS access to the CSM server to the few clients that actually need access to it, until a fix has been released. That way you can at least restrict the amount of clients that could utilize this leak.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Apr 2014 07:45:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-security-manager-is-vulnerable-to-cve-2014-0160-aka/m-p/2474464#M921846</guid>
      <dc:creator>patoberli</dc:creator>
      <dc:date>2014-04-15T07:45:38Z</dc:date>
    </item>
    <item>
      <title>Hi Ahmed,CSM 4.4.0 SP2 patch</title>
      <link>https://community.cisco.com/t5/network-security/cisco-security-manager-is-vulnerable-to-cve-2014-0160-aka/m-p/2474465#M921847</link>
      <description>&lt;P&gt;Hi Ahmed,&lt;/P&gt;&lt;P&gt;CSM 4.4.0 SP2 patch 1 is not vulnerable to heartbleed. No action required for this specific version of CSM.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Given below is list of CSM versions that are vulnerable:&lt;/P&gt;&lt;P&gt;CSM 4.5&lt;BR /&gt;CSM 4.5 SP0 PP1&lt;BR /&gt;CSM 4.5 SP0 PP2&lt;/P&gt;</description>
      <pubDate>Wed, 16 Apr 2014 04:37:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-security-manager-is-vulnerable-to-cve-2014-0160-aka/m-p/2474465#M921847</guid>
      <dc:creator>kshiva</dc:creator>
      <dc:date>2014-04-16T04:37:47Z</dc:date>
    </item>
    <item>
      <title>I am running 4.5.0, it is</title>
      <link>https://community.cisco.com/t5/network-security/cisco-security-manager-is-vulnerable-to-cve-2014-0160-aka/m-p/2474466#M921849</link>
      <description>&lt;P&gt;I am running 4.5.0, it is vulnerable because I have scanned it and tested it. I see version 4.6.0 has just popped up on cisco.com. Anyone confirm if that fixes the bug?&lt;/P&gt;</description>
      <pubDate>Wed, 16 Apr 2014 04:43:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-security-manager-is-vulnerable-to-cve-2014-0160-aka/m-p/2474466#M921849</guid>
      <dc:creator>Network Operation</dc:creator>
      <dc:date>2014-04-16T04:43:29Z</dc:date>
    </item>
    <item>
      <title>CSM 4.6 has the fix and not</title>
      <link>https://community.cisco.com/t5/network-security/cisco-security-manager-is-vulnerable-to-cve-2014-0160-aka/m-p/2474467#M921851</link>
      <description>&lt;P&gt;CSM 4.6 has the fix and not vulnerable.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Apr 2014 04:56:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-security-manager-is-vulnerable-to-cve-2014-0160-aka/m-p/2474467#M921851</guid>
      <dc:creator>kshiva</dc:creator>
      <dc:date>2014-04-16T04:56:07Z</dc:date>
    </item>
    <item>
      <title>Im not sure if that's true.</title>
      <link>https://community.cisco.com/t5/network-security/cisco-security-manager-is-vulnerable-to-cve-2014-0160-aka/m-p/2474468#M921852</link>
      <description>&lt;P&gt;Im not sure if that's true. the release notes don't state anything about fixing that big. and also looking at the opensource licenses PDF for 4.6.0 it states OpenSSL version: 1.0.1e (which is the same version as 4.5.0 and all versions 1a through 1f are vulnerable).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would find it very odd they didn't fix it considering it was released just yesterday.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Apr 2014 05:00:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-security-manager-is-vulnerable-to-cve-2014-0160-aka/m-p/2474468#M921852</guid>
      <dc:creator>ryancisco01</dc:creator>
      <dc:date>2014-04-16T05:00:29Z</dc:date>
    </item>
    <item>
      <title>Will follow up and update the</title>
      <link>https://community.cisco.com/t5/network-security/cisco-security-manager-is-vulnerable-to-cve-2014-0160-aka/m-p/2474469#M921853</link>
      <description>&lt;P&gt;Will follow up and update the documentation with correct OpenSSL Version 1.0.1g. Heartbleed vulnerability is addressed in CSM 4.6&lt;/P&gt;</description>
      <pubDate>Wed, 16 Apr 2014 05:08:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-security-manager-is-vulnerable-to-cve-2014-0160-aka/m-p/2474469#M921853</guid>
      <dc:creator>kshiva</dc:creator>
      <dc:date>2014-04-16T05:08:00Z</dc:date>
    </item>
    <item>
      <title>Great thanks for confirmation</title>
      <link>https://community.cisco.com/t5/network-security/cisco-security-manager-is-vulnerable-to-cve-2014-0160-aka/m-p/2474470#M921854</link>
      <description>&lt;P&gt;Great thanks for confirmation.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Apr 2014 05:40:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-security-manager-is-vulnerable-to-cve-2014-0160-aka/m-p/2474470#M921854</guid>
      <dc:creator>ryancisco01</dc:creator>
      <dc:date>2014-04-16T05:40:57Z</dc:date>
    </item>
    <item>
      <title>Many thanks </title>
      <link>https://community.cisco.com/t5/network-security/cisco-security-manager-is-vulnerable-to-cve-2014-0160-aka/m-p/2474471#M921855</link>
      <description>&lt;P&gt;Many thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Apr 2014 09:27:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-security-manager-is-vulnerable-to-cve-2014-0160-aka/m-p/2474471#M921855</guid>
      <dc:creator>ahmed.gadi</dc:creator>
      <dc:date>2014-04-16T09:27:56Z</dc:date>
    </item>
    <item>
      <title>When will the patch to</title>
      <link>https://community.cisco.com/t5/network-security/cisco-security-manager-is-vulnerable-to-cve-2014-0160-aka/m-p/2474472#M921856</link>
      <description>&lt;P&gt;When will the patch to resolve heartbleed issue in csm 4.5 be out??&lt;/P&gt;</description>
      <pubDate>Wed, 16 Apr 2014 13:51:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-security-manager-is-vulnerable-to-cve-2014-0160-aka/m-p/2474472#M921856</guid>
      <dc:creator>Tan Stanley</dc:creator>
      <dc:date>2014-04-16T13:51:55Z</dc:date>
    </item>
    <item>
      <title>CSM 4.5 CP3 is out and it</title>
      <link>https://community.cisco.com/t5/network-security/cisco-security-manager-is-vulnerable-to-cve-2014-0160-aka/m-p/2474473#M921857</link>
      <description>&lt;P&gt;CSM 4.5 CP3 is out and it fixes the heartbleed vulnerability.&lt;/P&gt;&lt;P&gt;Request CSM450_SP0_CP3_bundle.zip from TAC&lt;/P&gt;</description>
      <pubDate>Mon, 21 Apr 2014 03:56:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-security-manager-is-vulnerable-to-cve-2014-0160-aka/m-p/2474473#M921857</guid>
      <dc:creator>dbrockus</dc:creator>
      <dc:date>2014-04-21T03:56:10Z</dc:date>
    </item>
  </channel>
</rss>

