PT-1999-1573 · Cisco · Cisco Pix Private Link
Published
1999-12-31
·
Updated
2017-10-10
·
CVE-1999-1100
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Cisco PIX Private Link version 4.1.6 and earlier
Description
The issue arises from improper processing of certain commands in the configuration file, which reduces the effective key length of the DES key to 48 bits instead of 56 bits. This reduction makes it easier for an attacker to find the proper key via a brute force attack.
Recommendations
For Cisco PIX Private Link version 4.1.6 and earlier, update to a version that properly processes commands in the configuration file to ensure the full 56-bit key length is utilized.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Pix Private Link