CVE-2013-1194: Infoleak
The ISAKMP implementation on Cisco Adaptive Security Appliances (ASA) devices generates different responses for IKE aggressive-mode messages depending on whether invalid VPN groups are specified, which allows remote attackers to enumerate groups via a series of messages, aka Bug ID CSCue73708.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1194?
CVE-2013-1194 is classified as a moderate severity vulnerability.
How do I fix CVE-2013-1194?
To remediate CVE-2013-1194, ensure that Cisco Adaptive Security Appliance software is updated to the latest version that addresses this vulnerability.
What devices are affected by CVE-2013-1194?
CVE-2013-1194 affects Cisco Adaptive Security Appliances (ASA) that implement ISAKMP.
What impact does CVE-2013-1194 have on security?
CVE-2013-1194 allows remote attackers to enumerate VPN groups, potentially leading to unauthorized access.
Is CVE-2013-1194 exploited in the wild?
As of the latest data, there is no reported exploitation of CVE-2013-1194 in the wild.