—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA1
Cisco Security Advisory: Cisco ASA Software Internet Key Exchange Version 1 XAUTH Denial of Service Vulnerability
Advisory ID: cisco-sa-20170419-asa-xauth
Revision: 1.0
For Public Release: 2017 April 19 16:00 GMT
Last Updated: 2017 April 19 16:00 GMT
CVE ID(s): CVE-2017-6610
CVSS Score v(3): 7.7 CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
+———————————————————————
Summary
=======
A vulnerability in the Internet Key Exchange Version 1 (IKEv1) XAUTH code of Cisco ASA Software could allow an authenticated, remote attacker to cause a reload of an affected system.
The vulnerability is due to insufficient validation of the IKEv1 XAUTH parameters passed during an IKEv1 negotiation. An attacker could exploit this vulnerability by sending crafted parameters.
Note: Only traffic directed to the affected system can be used to exploit this vulnerability. This vulnerability only affects systems configured in routed firewall mode and in single or multiple context mode. This vulnerability can be triggered by IPv4 or IPv6 traffic. A valid IKEv1 Phase 1 needs to be established to exploit this vulnerability, which means that an attacker would need to have knowledge of a pre-shared key or have a valid certificate for phase 1 authentication.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170419-asa-xauth [“https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170419-asa-xauth”]
—–BEGIN PGP SIGNATURE—–
iQKBBAEBAgBrBQJY94zEZBxDaXNjbyBTeXN0ZW1zIFByb2R1Y3QgU2VjdXJpdHkg
SW5jaWRlbnQgUmVzcG9uc2UgVGVhbSAoQ2lzY28gUFNJUlQga2V5IDIwMTYtMjAx
NykgPHBzaXJ0QGNpc2NvLmNvbT4ACgkQrz2APcQAkHnO1w/+Ix6KNGqY7EIckP18
H8xH5UvJhdGrhsZEesqzte6xzBvxK04dJUjL4xGiii9CSklb9OH6r7JO9BGAcsjk
GgtT21erl1fbjrlwJivIak8FaOnqubdQC4PT9A9o7Doxcg6g6Ny940EIeIfEUTgT
Ijw08xFGOTUZKIyCn+FGiNfDIL1PsMaK4I1QQML73HHVgOjIX64UH2IGtGDCq/Vp
Uku1UES0BKA2CE/GNuSMbCuti4f4Eml6tsDKY0Yncxm33My/zbuwS2Vag5X3BH9Y
48XHZ6BX3J/4u5n9j7qYOLQv/83VQdOzUVevdtdJ3DmpVECRyjm9/ZIGwMx5pnm3
m2oHkHP51aXnOURFUx70LZDmnkK39rQRI4GGnYE3c4zvJkaJWD1UQlSRl8/T4cI2
FYjceOGDvRes46OlhIKWCIKFp+Y6jP+q2svV6HRWRXc6YzLekn4eFzc4CersX2Sf
U8wo8JsIzi0ZPbIUbvVrHV6vaCwodiLhHDELachqj+G+THXQPSn9bD1qzTy51MlG
5x4eSxKA6xB9mDdNsvxA/y4edNBSHOwFXnCsWJ6+0KYZcIvNmkzsx06xFr+V7bzA
rxou211T2q/QpDduErFjy27/Y7hhbf3T+Qv209hOYQ3LzUaj97ehZVAvsvYWYn5G
xdwISDOhMr8PJM9zxnIkNZY9IM0=
=UFZE
—–END PGP SIGNATURE—–
_______________________________________________
cust-security-announce mailing list
cust-security-announce@cisco.com
To unsubscribe, send the command “unsubscribe” in the subject of your message to cust-security-announce-leave@cisco.com