SB2023032326 - Key management errors in Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software
Published: March 23, 2023
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Key management errors (CVE-ID: CVE-2023-20107)
The vulnerability allows a remote attacker to cause a cryptographic collision.
The vulnerability exists due to insufficient entropy in the deterministic random bit generator (DRBG) for the affected hardware platforms when generating cryptographic keys. A remote attacker can generate a large number of cryptographic keys, discover the private key and decrypt traffic that is sent to or from the target device.
Remediation
Install update from vendor's website.