MEDIUM
The TLS implementation in the Cavium cryptographic-module firmware, as distributed with Cisco Adaptive Security Appliance (ASA) Software 9.1(5.21) and other products, does not verify the MAC field, which allows man-in-the-middle attackers to spoof TLS content by modifying packets, aka Bug ID CSCuu52976
Published Jul 18, 2015
4.3
MEDIUMCVSS 2.0
EPSS 0.99%
Description
Affected products
Remediation
Metrics
References (2)
Change history (0)
No recorded changes yet.