05-24-2016 12:56 AM - edited 03-12-2019 12:47 AM
Hi Guys,
It seems there is a openssl Vulnerability for ASA. How to patch it, for ASA version 9.4.1 and is there any software update for it.
Regards,
G.Pitchaimani
05-24-2016 02:09 AM
Hi,
Could you please share the CVE id of the vulnerability which you are trying to patch.
Thanks,
RS
05-24-2016 03:00 AM
Hi,
05-24-2016 06:53 AM
Hi,
Cisco ASA running release 9.0 or later may be affected by the following vulnerabilities.
Exposure is not configuration dependent.
Padding oracle in AES-NI
Memory corruption in the ASN.1 encoder CVE-2016-2108
ASN.1 BIO excessive memory allocation CVE-2016-2109
The ASA is not affected by the following vulnerabilities:
EVP_EncodeUpdate overflow CVE-2016-2105
EVP_EncryptUpdate overflow CVE-2016-2106
EBCDIC overread CVE-2016-2176
So while the ASA is not affected by the last 3, it may be affected by the first 3. There is no fixed version available yet but
https://bst.cloudapps.cisco.com/bugsearch/bug/CSCuz52474/?reffering_site=dumpcr
Regards,
Aditya
Please rate helpful posts and mark correct answers.
05-26-2016 06:09 AM
05-26-2016 06:34 AM
Hi,
This being a Severity 2 bug expect a fix soon on this.
Apologies but I do not have an exact ETA for this.
Regards,
Aditya
Please rate helpful posts and mark correct answers.
06-01-2016 12:24 AM
Hi,
Is there any patch came for these vulnerabilities.
Regards,
G.Pitchaimani
06-13-2016 10:21 AM
Hi,
Is there any update on OpenSSL vulnerabilities. Is there any patch available for OpenSSL Vulnerabilities.
Regards,
G.Pitchaimani
06-13-2016 05:44 PM
Hi,
The bug has been resolved and the fixed versions are listed in the bug details.
https://bst.cloudapps.cisco.com/bugsearch/bug/CSCuz52474/?reffering_site=dumpcr
You can upgrade to the fixed versions to overcome this bug impact.
Regards,
Aditya
Please rate helpful posts and mark correct answers.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide