cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
315
Views
0
Helpful
1
Replies

CSCuu83280 - Evaluation of OpenSSL - ASA 9.4(4)18

Daprafue_79
Beginner
Beginner

We are using ASA 5585 with version 9.4(4)18 but this version doesn't appear neither affected or Fixed versions. Could anybody tell me if this version could be affected?

 

Thanks!!! 

1 Accepted Solution

Accepted Solutions

Seb Rupik
VIP Advisor VIP Advisor
VIP Advisor

HI there,

Sadly you have to do a bit of sleuthing to work this out. The CVE relating to your bug:

 https://nvd.nist.gov/vuln/detail/CVE-2015-1790

 

…mentions the openSSL versions vulnerable…

The opensource software for 9.4(1):

https://www.cisco.com/c/dam/en/us/td/docs/security/asa/asa94/license/open-source/Cisco_ASA_Series_941.pdf

 

…states that it uses 1.0.1l , so this version is vulnerable.

 

The patch notes for 9.4(4)18 do not mention the original CVE, but does mention for following CVE as being fixed in 9.4(4)17:

https://nvd.nist.gov/vuln/detail/CVE-2017-3737

 

..which mentions openSSL 1.0.2b

 

So…we can infer that the 9.4.(4)18 is running a newer version of openSSL 1.0.2b and therefore is not vulnerable to CSCuu83280.

 

:)

 

Cheers,

Seb.

View solution in original post

1 Reply 1

Seb Rupik
VIP Advisor VIP Advisor
VIP Advisor

HI there,

Sadly you have to do a bit of sleuthing to work this out. The CVE relating to your bug:

 https://nvd.nist.gov/vuln/detail/CVE-2015-1790

 

…mentions the openSSL versions vulnerable…

The opensource software for 9.4(1):

https://www.cisco.com/c/dam/en/us/td/docs/security/asa/asa94/license/open-source/Cisco_ASA_Series_941.pdf

 

…states that it uses 1.0.1l , so this version is vulnerable.

 

The patch notes for 9.4(4)18 do not mention the original CVE, but does mention for following CVE as being fixed in 9.4(4)17:

https://nvd.nist.gov/vuln/detail/CVE-2017-3737

 

..which mentions openSSL 1.0.2b

 

So…we can infer that the 9.4.(4)18 is running a newer version of openSSL 1.0.2b and therefore is not vulnerable to CSCuu83280.

 

:)

 

Cheers,

Seb.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Recognize Your Peers