CVE-2015-4458: Cisco Adaptive Security Appliance Software
Medium severity, CVSS 4.3. EPSS: 1% chance of exploitation in the next 30 days.
The TLS implementation in the Cavium cryptographic-module firmware, as distributed with Cisco Adaptive Security Appliance (ASA) Software 9.1(5.21) and other products, does not verify the MAC field, which allows man-in-the-middle attackers to spoof TLS content by modifying packets, aka Bug ID CSCuu52976.
Affected products
- Cisco Adaptive Security Appliance Software: version 9.1.5.21 only
Published 2015-07-18. Last modified 2026-06-17.