Cisco.Pix.IKE.Information.Disclosure

description-logoDescription

This indicates an attack attempt against an Information Disclosure vulnerability in Cisco PIX.
The vulnerability is due to insufficient input validation in the application when handling a crafted ISAKMP request. The attacker can exploit this to extract an RSA private key and other sensitive configuration information from a vulnerable server by sending crafted ISAKMP requests.

affected-products-logoAffected Products

Cisco PIX pre version 7.0

Impact logoImpact

Information Disclosure: Remote attackers can gain sensitive information from vulnerable systems.

recomended-action-logoRecommended Actions

Currenty we are unaware of any officially released patch or update for this issue.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)