CSCuu83280 - Evaluation of OpenSSL - ASA 9.4(4)18
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-18-2018 03:06 AM
We are using ASA 5585 with version 9.4(4)18 but this version doesn't appear neither affected or Fixed versions. Could anybody tell me if this version could be affected?
Thanks!!!
Solved! Go to Solution.
- Labels:
-
Cisco Bugs
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-18-2018 03:32 AM - edited 10-18-2018 03:40 AM
HI there,
Sadly you have to do a bit of sleuthing to work this out. The CVE relating to your bug:
https://nvd.nist.gov/vuln/detail/CVE-2015-1790
…mentions the openSSL versions vulnerable…
The opensource software for 9.4(1):
…states that it uses 1.0.1l , so this version is vulnerable.
The patch notes for 9.4(4)18 do not mention the original CVE, but does mention for following CVE as being fixed in 9.4(4)17:
https://nvd.nist.gov/vuln/detail/CVE-2017-3737
..which mentions openSSL 1.0.2b
So…we can infer that the 9.4.(4)18 is running a newer version of openSSL 1.0.2b and therefore is not vulnerable to CSCuu83280.
:)
Cheers,
Seb.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-18-2018 03:32 AM - edited 10-18-2018 03:40 AM
HI there,
Sadly you have to do a bit of sleuthing to work this out. The CVE relating to your bug:
https://nvd.nist.gov/vuln/detail/CVE-2015-1790
…mentions the openSSL versions vulnerable…
The opensource software for 9.4(1):
…states that it uses 1.0.1l , so this version is vulnerable.
The patch notes for 9.4(4)18 do not mention the original CVE, but does mention for following CVE as being fixed in 9.4(4)17:
https://nvd.nist.gov/vuln/detail/CVE-2017-3737
..which mentions openSSL 1.0.2b
So…we can infer that the 9.4.(4)18 is running a newer version of openSSL 1.0.2b and therefore is not vulnerable to CSCuu83280.
:)
Cheers,
Seb.
