firewall
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-24-2016 12:56 AM - edited 03-12-2019 12:47 AM
Hi Guys,
It seems there is a openssl Vulnerability for ASA. How to patch it, for ASA version 9.4.1 and is there any software update for it.
Regards,
G.Pitchaimani
- Labels:
-
NGFW Firewalls
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-24-2016 02:09 AM
Hi,
Could you please share the CVE id of the vulnerability which you are trying to patch.
Thanks,
RS
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-24-2016 03:00 AM
Hi,

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-24-2016 06:53 AM
Hi,
Cisco ASA running release 9.0 or later may be affected by the following vulnerabilities.
Exposure is not configuration dependent.
Padding oracle in AES-NI
Memory corruption in the ASN.1 encoder CVE-2016-2108
ASN.1 BIO excessive memory allocation CVE-2016-2109
The ASA is not affected by the following vulnerabilities:
EVP_EncodeUpdate overflow CVE-2016-2105
EVP_EncryptUpdate overflow CVE-2016-2106
EBCDIC overread CVE-2016-2176
So while the ASA is not affected by the last 3, it may be affected by the first 3. There is no fixed version available yet but
https://bst.cloudapps.cisco.com/bugsearch/bug/CSCuz52474/?reffering_site=dumpcr
Regards,
Aditya
Please rate helpful posts and mark correct answers.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-26-2016 06:09 AM

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-26-2016 06:34 AM
Hi,
This being a Severity 2 bug expect a fix soon on this.
Apologies but I do not have an exact ETA for this.
Regards,
Aditya
Please rate helpful posts and mark correct answers.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-01-2016 12:24 AM
Hi,
Is there any patch came for these vulnerabilities.
Regards,
G.Pitchaimani
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-13-2016 10:21 AM
Hi,
Is there any update on OpenSSL vulnerabilities. Is there any patch available for OpenSSL Vulnerabilities.
Regards,
G.Pitchaimani

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-13-2016 05:44 PM
Hi,
The bug has been resolved and the fixed versions are listed in the bug details.
https://bst.cloudapps.cisco.com/bugsearch/bug/CSCuz52474/?reffering_site=dumpcr
You can upgrade to the fixed versions to overcome this bug impact.
Regards,
Aditya
Please rate helpful posts and mark correct answers.
