cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2380
Views
0
Helpful
2
Replies

Vulnerability in Cisco ASA

walter.perera
Level 1
Level 1

Hi all:

Executing a Vulnerability Assessment in an ASA 5510, it has detected a "SSL / TLS Renegotiation Handshakes MiTM Plaintext Data Injection". As a recommendation, it suggest to contact the supplier to find any patch. As of now, we couldn't find any patch.

Could you please help us?

IOS ver is Cisco Adaptive Security Appliance Software Version 8.0(3)6
asa803-6-k8.bin

Thanks

2 Replies 2

Farrukh Haroon
VIP Alumni
VIP Alumni

Download the latest ASA code and disable SSH V1 on your ASA.

It should fix it (if there is any issue in the first place)!


Regards

Farrukh

This is the one you are talking about: http://www.cisco.com/warp/public/707/cisco-sa-20080604-asa.shtml

fixed in 8.0.3(9) and on.

You can download the code here: http://tools.cisco.com/support/downloads/go/Redirect.x?mdfid=268438162

-KS

Review Cisco Networking products for a $25 gift card