Missing Required Cryptographic Step in Cisco Firewall Threat Defense (FTD) and Cisco Adaptive Security Appliance (ASA) - CVE-2022-20742
Published: April 27, 2022
Vulnerability details
The vulnerability allows a remote attacker to read or modify data within an IPsec IKEv2 VPN tunnel.
The vulnerability exists due to improper implementation of Galois/Counter Mode (GCM) ciphers in an IPsec VPN library. A remote attacker can perform MitM attack by intercepting a sufficient number of encrypted messages across an affected IPsec IKEv2 VPN tunnel and then using cryptanalytic techniques to break the encryption.
Affected software
Cisco Adaptive Security Appliance (ASA)
How to mitigate CVE-2022-20742
Cisco Adaptive Security Appliance (ASA) - addressed in versions 9.12.4.37, 9.14.3.13, 9.15.1.21, 9.16.2.7