Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A vulnerability in the implementation of RSA-encrypted nonces in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to obtain the encrypted nonces of an Internet Key Exchange Version 1 (IKEv1) session. The vulnerability exists because the affected software responds incorrectly to decryption failures. An attacker could exploit this vulnerability sending crafted ciphertexts to a device configured with IKEv1 that uses RSA-encrypted nonces. A successful exploit could allow the attacker to obtain the encrypted nonces. Cisco Bug IDs: CSCve77140.
CVSS Information
N/A
Vulnerability Type
不充分的加密强度
Vulnerability Title
Cisco IOS Software和Cisco IOS XE Software 安全漏洞
Vulnerability Description
Cisco IOS Software和IOS XE Software都是美国思科(Cisco)公司为其网络设备开发的操作系统。 Cisco IOS Software和Cisco IOS XE Software中被RSA加密的未知数的实现存在安全漏洞,该漏洞源于程序没有正确的响应加密失败的情况。远程攻击者可通过发送特制的密文利用该漏洞获取IKEv1(互联网密钥交换协议1版本)会话的被加密未知数。
CVSS Information
N/A
Vulnerability Type
N/A