<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Do i need to patch my asa ? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/do-i-need-to-patch-my-asa/m-p/3363540#M962882</link>
    <description>&lt;DIV class="usertext-body may-blank-within md-container "&gt;
&lt;DIV class="md"&gt;
&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I have a cisco asa 5525 and I found out there is a vulnerability ( cisco-sa-20180129-asa1 ) and I dont know if my version is vulnerable (my version is 9.6.3) . According to this site ( &lt;A href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180129-asa1#fixed" target="_blank"&gt;https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180129-asa1#fixed&lt;/A&gt; ) I think it is vulnerable but I'm not sure. Can you guys please help me ? Thanks a lot.&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
    <pubDate>Fri, 21 Feb 2020 15:37:04 GMT</pubDate>
    <dc:creator>toxqsd</dc:creator>
    <dc:date>2020-02-21T15:37:04Z</dc:date>
    <item>
      <title>Do i need to patch my asa ?</title>
      <link>https://community.cisco.com/t5/network-security/do-i-need-to-patch-my-asa/m-p/3363540#M962882</link>
      <description>&lt;DIV class="usertext-body may-blank-within md-container "&gt;
&lt;DIV class="md"&gt;
&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I have a cisco asa 5525 and I found out there is a vulnerability ( cisco-sa-20180129-asa1 ) and I dont know if my version is vulnerable (my version is 9.6.3) . According to this site ( &lt;A href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180129-asa1#fixed" target="_blank"&gt;https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180129-asa1#fixed&lt;/A&gt; ) I think it is vulnerable but I'm not sure. Can you guys please help me ? Thanks a lot.&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:37:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/do-i-need-to-patch-my-asa/m-p/3363540#M962882</guid>
      <dc:creator>toxqsd</dc:creator>
      <dc:date>2020-02-21T15:37:04Z</dc:date>
    </item>
    <item>
      <title>Re: Do i need to patch my asa ?</title>
      <link>https://community.cisco.com/t5/network-security/do-i-need-to-patch-my-asa/m-p/3363548#M962883</link>
      <description>&lt;P&gt;9.6.3 is an affected release. But the vulnerability can only be exploited if you have one of the features enabled as documented in the vulnerability documentation:&lt;/P&gt;
&lt;TABLE border="3" cellspacing="0" cellpadding="6"&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TH&gt;&lt;SPAN&gt;&lt;STRONG&gt;Feature&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TH&gt;
&lt;TH&gt;&lt;SPAN&gt;&lt;STRONG&gt;Vulnerable Configuration&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;Adaptive Security Device Manager (ASDM)&lt;SUP&gt;1&lt;/SUP&gt;&lt;/TD&gt;
&lt;TD&gt;http server enable &amp;lt;port&amp;gt;&lt;BR /&gt;http &amp;lt;remote_ip_address&amp;gt; &amp;lt;remote_subnet_mask&amp;gt; &amp;lt;interface_name&amp;gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;AnyConnect IKEv2 Remote Access (with client services)&lt;/TD&gt;
&lt;TD&gt;crypto ikev2 enable &amp;lt;interface_name&amp;gt; client-services port &amp;lt;port #&amp;gt;&lt;BR /&gt;webvpn&lt;BR /&gt;&amp;nbsp;&amp;nbsp; anyconnect enable&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;AnyConnect IKEv2 Remote Access (without client services)&lt;/TD&gt;
&lt;TD&gt;crypto ikev2 enable &amp;lt;interface_name&amp;gt;&lt;BR /&gt;webvpn&lt;BR /&gt;&amp;nbsp;&amp;nbsp; anyconnect enable&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;AnyConnect SSL VPN&lt;/TD&gt;
&lt;TD&gt;webvpn&lt;BR /&gt;&amp;nbsp;&amp;nbsp; enable &amp;lt;interface_name&amp;gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Cisco Security Manager&lt;SUP&gt;2&lt;/SUP&gt;&lt;/TD&gt;
&lt;TD&gt;http server enable &amp;lt;port&amp;gt;&lt;BR /&gt;http &amp;lt;remote_ip_address&amp;gt; &amp;lt;remote_subnet_mask&amp;gt; &amp;lt;interface_name&amp;gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Clientless SSL VPN&lt;/TD&gt;
&lt;TD&gt;webvpn&lt;BR /&gt;&amp;nbsp;&amp;nbsp; enable &amp;lt;interface_name&amp;gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Cut-Through Proxy (Not vulnerable unless used in conjunction with other vulnerable features on the same port)&lt;/TD&gt;
&lt;TD&gt;aaa authentication listener &amp;lt;interface_name&amp;gt; port &amp;lt;number&amp;gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Local Certificate Authority (CA)&lt;/TD&gt;
&lt;TD&gt;crypto ca server&lt;BR /&gt;&amp;nbsp;no shutdown&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Mobile Device Manager (MDM) Proxy&lt;SUP&gt;3&lt;/SUP&gt;&lt;/TD&gt;
&lt;TD&gt;mdm-proxy&lt;BR /&gt;&amp;nbsp; enable &amp;lt;interface_name&amp;gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Mobile User Security (MUS)&lt;/TD&gt;
&lt;TD&gt;webvpn&lt;BR /&gt;&amp;nbsp;mus password &amp;lt;password&amp;gt;&lt;BR /&gt;&amp;nbsp;mus server enable port &amp;lt;port #&amp;gt;&lt;BR /&gt;&amp;nbsp;mus &amp;lt;address&amp;gt; &amp;lt;mask&amp;gt; &amp;lt;interface_name&amp;gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Proxy Bypass&lt;/TD&gt;
&lt;TD&gt;webvpn&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp; proxy-bypass&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;REST API&lt;SUP&gt;4&lt;/SUP&gt;&lt;/TD&gt;
&lt;TD&gt;rest-api image disk0:/&amp;lt;image name&amp;gt;&lt;BR /&gt;rest-api agent&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Security Assertion Markup Language (SAML) Single Sign-On (SSO)&lt;SUP&gt;5&lt;/SUP&gt;&lt;/TD&gt;
&lt;TD&gt;N/A&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;An upgrade to 9.6.4.3 is recommended if you any of the above features enabled.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Apr 2018 15:52:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/do-i-need-to-patch-my-asa/m-p/3363548#M962883</guid>
      <dc:creator>Rahul Govindan</dc:creator>
      <dc:date>2018-04-10T15:52:34Z</dc:date>
    </item>
  </channel>
</rss>

