Missing Required Cryptographic Step in Cisco Firewall Threat Defense (FTD) and Cisco Adaptive Security Appliance (ASA) - CVE-2022-20742

 

Missing Required Cryptographic Step in Cisco Firewall Threat Defense (FTD) and Cisco Adaptive Security Appliance (ASA) - CVE-2022-20742

Published: April 27, 2022


Vulnerability identifier: #VU62669
CSH Severity: Medium
CVSS v4: 7.6 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-20742
CWE-ID: CWE-325
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to read or modify data within an IPsec IKEv2 VPN tunnel.

The vulnerability exists due to improper implementation of Galois/Counter Mode (GCM) ciphers in an IPsec VPN library. A remote attacker can perform MitM attack by intercepting a sufficient number of encrypted messages across an affected IPsec IKEv2 VPN tunnel and then using cryptanalytic techniques to break the encryption.


Affected software

Cisco Firewall Threat Defense (FTD)
Cisco Adaptive Security Appliance (ASA)

How to mitigate CVE-2022-20742

Install updates from vendor's website.

Cisco Firewall Threat Defense (FTD) - addressed in versions 6.4.0.13, 6.6.5.1, 6.7.0.4, 7.0.2
Cisco Adaptive Security Appliance (ASA) - addressed in versions 9.12.4.37, 9.14.3.13, 9.15.1.21, 9.16.2.7

External References

Related Security Bulletins