Key management errors in Cisco Systems, Inc products - CVE-2023-20107
Published: March 23, 2023
Adaptive Security Appliance 5506-X
Adaptive Security Appliance 5506H-X
Adaptive Security Appliance 5506W-X
Adaptive Security Appliance 5508-X
Adaptive Security Appliance 5516-X
Cisco Adaptive Security Appliance (ASA)
Cisco Firewall Threat Defense (FTD)
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to cause a cryptographic collision.
The vulnerability exists due to insufficient entropy in the deterministic random bit generator (DRBG) for the affected hardware platforms when generating cryptographic keys. A remote attacker can generate a large number of cryptographic keys, discover the private key and decrypt traffic that is sent to or from the target device.