Blog | G5 Cyber Security

Critical VPN key exchange flaw exposes Cisco security appliances to remote hacking

Cisco Systems patched a critical vulnerability that could allow remote attackers to take over Cisco firewalls. The flaw is located in the Cisco ASA code that handles the Internet Key Exchange version 1 (IKEv1) and IKEv2) protocols. The vulnerability stems from a buffer overflow condition in the function that processes fragmented IKE payloads. Cisco rated the vulnerability with the maximum score of 10 in the Common Vulnerability Scoring System. Users are advised to update as soon as possible.”]

Source: https://www.csoonline.com/article/3031389/critical-vpn-key-exchange-flaw-exposes-cisco-security-appliances-to-remote-hacking.html

Exit mobile version