PT-1999-1573 · Cisco · Cisco Pix Private Link

Published

1999-12-31

·

Updated

2017-10-10

·

CVE-1999-1100

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Cisco PIX Private Link version 4.1.6 and earlier
Description The issue arises from improper processing of certain commands in the configuration file, which reduces the effective key length of the DES key to 48 bits instead of 56 bits. This reduction makes it easier for an attacker to find the proper key via a brute force attack.
Recommendations For Cisco PIX Private Link version 4.1.6 and earlier, update to a version that properly processes commands in the configuration file to ensure the full 56-bit key length is utilized.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-1999-1100

Affected Products

Cisco Pix Private Link