CVE-2015-4550: Cisco Adaptive Security Appliance Software
Medium severity, CVSS 4.3. EPSS: 1.3% chance of exploitation in the next 30 days.
The Cavium cryptographic-module firmware on Cisco Adaptive Security Appliance (ASA) devices with software 9.3(3) and 9.4(1.1) does not verify the AES-GCM Integrity Check Value (ICV) octets, which makes it easier for man-in-the-middle attackers to spoof IPSec and IKEv2 traffic by modifying packet data, aka Bug ID CSCuu66218.
Affected products
- Cisco Adaptive Security Appliance Software: version 9.3(3) only; version 9.4(1.1) only
Published 2015-06-17. Last modified 2026-06-17.