Total vulnerabilities in the database
Cisco PIX Firewall 6.0.3 and earlier, and 6.1.x to 6.1.3, do not delete the duplicate ISAKMP SAs for a user's VPN session, which allows local users to hijack a session via a man-in-the-middle attack.
Software | From | Fixed in |
---|---|---|
cisco / pix_firewall_software | 6.0(1) | 6.0(1).x |
cisco / pix_firewall_software | 6.0(2) | 6.0(2).x |
cisco / pix_firewall_software | 6.0 | 6.0.x |
cisco / pix_firewall_software | 6.0(3) | 6.0(3).x |
cisco / pix_firewall_software | 6.1 | 6.1.x |
cisco / pix_firewall_software | 6.1(2) | 6.1(2).x |
cisco / pix_firewall_software | 6.1(3) | 6.1(3).x |