CVE-2011-3309: Infoleak
Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.2 through 8.4 process IKE requests despite a vpnclient mode configuration, which allows remote attackers to obtain potentially sensitive information by reading IKE responder traffic, aka Bug ID CSCtt07749.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-3309?
CVE-2011-3309 is considered a moderate severity vulnerability.
How do I fix CVE-2011-3309?
To address CVE-2011-3309, upgrading to a fixed version of the Cisco Adaptive Security Appliance software is recommended.
What devices are affected by CVE-2011-3309?
CVE-2011-3309 affects Cisco Adaptive Security Appliances 5500 series running software versions 8.2 through 8.4.
What type of attack can exploit CVE-2011-3309?
CVE-2011-3309 can be exploited by remote attackers to read potentially sensitive information from IKE responder traffic.
Is CVE-2011-3309 related to VPN security?
Yes, CVE-2011-3309 involves a vulnerability in IKE requests within VPN client mode configurations.