PT-2018-1452 · Cisco · Cisco Ios Xe+1

Published

2018-08-13

·

Updated

2019-10-09

·

CVE-2018-0131

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cisco IOS and Cisco IOS XE (affected versions not specified)
Description The issue is related to errors in decrypting traffic in the implementation of the Internet Key Exchange (IKE) protocol in Cisco IOS and Cisco IOS XE. This could allow a remote attacker to obtain session keys and decrypt traffic by sending specially crafted data packets to the device. The vulnerability exists because the affected software responds incorrectly to decryption failures, allowing an attacker to exploit this by sending crafted ciphertexts to a device configured with IKEv1 that uses RSA-encrypted nonces. A successful exploit could allow the attacker to obtain the encrypted nonces.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Inadequate Encryption Strength

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2018-01003
CVE-2018-0131

Affected Products

Cisco Ios
Cisco Ios Xe