PT-1999-1573 · Cisco · Cisco Pix Private Link
Publicado
1999-12-31
·
Atualizado
2017-10-10
·
CVE-1999-1100
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Cisco PIX Private Link version 4.1.6 and earlier
Description
The issue arises from improper processing of certain commands in the configuration file, which reduces the effective key length of the DES key to 48 bits instead of 56 bits. This reduction makes it easier for an attacker to find the proper key via a brute force attack.
Recommendations
For Cisco PIX Private Link version 4.1.6 and earlier, update to a version that properly processes commands in the configuration file to ensure the full 56-bit key length is utilized.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Cisco Pix Private Link