cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1474
Views
5
Helpful
3
Replies

Evaluation of esa for OpenSSL May 2016

govindprashad
Level 1
Level 1

Does anyone has an idea about the progress for the bug fund in open ssl.

This product includes a version of OpenSSL that is affected by the vulnerability identified by one or more of the following Common Vulnerability and Exposures (CVE) IDs:

CVE-2016-2108 CVE-2016-2107 CVE-2016-2105 CVE-2016-2106 CVE-2016-2109 CVE-2016-2176

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCuz52363

1 Accepted Solution

Accepted Solutions

Mohit Soni
Cisco Employee
Cisco Employee

Hi Govind,

Unfortunately there is no workaround available to mitigate against this vulnerability at this time however from above mentioned defect page, you can click on "Add Notification" to receive updates via notifications email regarding status changes of this defect. This will allow you to know the workaround or when there has been a fixed version of AsyncOS released.


Regards,
Mohit Soni

View solution in original post

3 Replies 3

Mohit Soni
Cisco Employee
Cisco Employee

Hi Govind,

Unfortunately there is no workaround available to mitigate against this vulnerability at this time however from above mentioned defect page, you can click on "Add Notification" to receive updates via notifications email regarding status changes of this defect. This will allow you to know the workaround or when there has been a fixed version of AsyncOS released.


Regards,
Mohit Soni

Hi guys!

some progress?

Regards,

Vinicius Reis

Vinicius,

As per the below link

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160504-openssl

Async OS 10.5 for Cisco Email Security Appliance would carry a fix and current ETA is Dec 2016.

Thanks

Libin Varghese