First published: Wed Jan 15 2020(Updated: )
Cisco IronPort Web Security Appliance AsyncOS software prior to 7.5 has a SSL Certificate Caching vulnerability which could allow man-in-the-middle attacks
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IronPort Web Security Appliance | <7.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2012-0334.
The title of the vulnerability is 'Cisco IronPort Web Security Appliance AsyncOS software prior to 7.5 has a SSL Certificate Caching vulnerability'.
The severity of CVE-2012-0334 is medium with a CVSS score of 6.4.
The affected software is the Cisco IronPort Web Security Appliance with AsyncOS software prior to version 7.5.
The vulnerability allows for SSL Certificate Caching, which could potentially lead to man-in-the-middle attacks.
Upgrade to Cisco IronPort Web Security Appliance AsyncOS software version 7.5 or higher to mitigate this vulnerability.
You can find more information about this vulnerability at the following references: [http://www.securityfocus.com/bid/52981](http://www.securityfocus.com/bid/52981) and [https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/Cisco-SA-20120412-CVE-2012-0334](https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/Cisco-SA-20120412-CVE-2012-0334).