Vulnerability Description
The IKEv1 implementation in Cisco ASA Software 7.x, 8.0.x, 8.1.x, and 8.2.x before 8.2.2.13 allows remote authenticated users to bypass XAUTH authentication via crafted IKEv1 packets, aka Bug ID CSCus47259.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Adaptive Security Appliance Software | >= 7.0, < 8.2.2.13 |
Related Weaknesses (CWE)
References
- http://tools.cisco.com/security/center/viewAlert.x?alertId=39157Vendor Advisory
- http://www.securitytracker.com/id/1032473Third Party AdvisoryVDB Entry
- http://tools.cisco.com/security/center/viewAlert.x?alertId=39157Vendor Advisory
- http://www.securitytracker.com/id/1032473Third Party AdvisoryVDB Entry
FAQ
What is CVE-2015-0760?
CVE-2015-0760 is a vulnerability with a CVSS score of 4.0 (MEDIUM). The IKEv1 implementation in Cisco ASA Software 7.x, 8.0.x, 8.1.x, and 8.2.x before 8.2.2.13 allows remote authenticated users to bypass XAUTH authentication via crafted IKEv1 packets, aka Bug ID CSCus...
How severe is CVE-2015-0760?
CVE-2015-0760 has been rated MEDIUM with a CVSS base score of 4.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-0760?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Adaptive Security Appliance Software.