CVE-2015-4458: Cisco Adaptive Security Appliance Software

Medium severity, CVSS 4.3. EPSS: 1% chance of exploitation in the next 30 days.

The TLS implementation in the Cavium cryptographic-module firmware, as distributed with Cisco Adaptive Security Appliance (ASA) Software 9.1(5.21) and other products, does not verify the MAC field, which allows man-in-the-middle attackers to spoof TLS content by modifying packets, aka Bug ID CSCuu52976.

Affected products

  • Cisco Adaptive Security Appliance Software: version 9.1.5.21 only

Published 2015-07-18. Last modified 2026-06-17.