SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2015-0675

The failover ipsec implementation in Cisco Adaptive Security Appliance (ASA) Software 9.1 before 9.1(6), 9.2 before 9.2(3.3), and 9.3 before 9.3(3) does not properly validate failover communication messages, which allows remote attackers to reconfigure…

HIGH 8.3EPSS 0.96%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.96%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

The failover ipsec implementation in Cisco Adaptive Security Appliance (ASA) Software 9.1 before 9.1(6), 9.2 before 9.2(3.3), and 9.3 before 9.3(3) does not properly validate failover communication messages, which allows remote attackers to reconfigure an ASA device, and consequently obtain administrative control, by sending crafted UDP packets over the local network to the failover interface, aka Bug ID CSCur21069.

CVSS 2.0
8.3 HIGHAV:A/AC:L/Au:N/C:C/I:C/A:C
EPSS
0.96% probability · 60th percentile
CISA KEV
Not listed
Weakness
CWE-284
Affected
cisco/adaptive security appliance software
Source
psirt@cisco.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.