CVE-2019-1715 (CNNVD-201905-042)
中文标题:
Cisco Adaptive Security Appliance Software和Cisco Firepower Threat Defense Software 安全漏洞
英文标题:
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Low-Entropy Keys Vulnerability
漏洞描述
中文描述:
Cisco Firepower 4100 Series等都是美国思科(Cisco)公司的产品。Cisco Firepower 4100 Series是一款4100系列的防火墙设备。FTD Software是其中的一套提供下一代防火墙服务的统一软件。Cisco 3000 Series Industrial Security Appliances是一款3000系列防火墙设备。ASA Software是其中的一套防火墙和网络安全平台。该平台提供了对数据和网络资源的高度安全的访问等功能。Adaptive Security Appliance (ASA) 5500-X Series with FirePOWER Services是一款防火墙设备。 Cisco ASA Software 9.8版本,9.9版本和FTD Software 6.2.1版本,6.2.2版本,6.2.3版本中的Deterministic Random Bit Generator (DRBG)存在安全漏洞。远程攻击者可通过生成大量的加密密钥利用该漏洞获取设备的私钥。以下产品受到影响:Cisco 3000 Series Industrial Security Appliances (ISAs);Adaptive Security Appliance (ASA) 5500-X Series with FirePOWER Services;Adaptive Security Virtual Appliance (ASAv);Firepower 4100 Series;Firepower 9300 ASA Security Module;Firepower Threat Defense Virtual。
英文描述:
A vulnerability in the Deterministic Random Bit Generator (DRBG), also known as Pseudorandom Number Generator (PRNG), used in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a cryptographic collision, enabling the attacker to discover the private key of an affected device. The vulnerability is due to insufficient entropy in the DRBG when generating cryptographic keys. An attacker could exploit this vulnerability by generating a large number of cryptographic keys on an affected device and looking for collisions with target devices. A successful exploit could allow the attacker to impersonate an affected target device or to decrypt traffic secured by an affected key that is sent to or from an affected target device.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| Cisco | Cisco Adaptive Security Appliance (ASA) Software | - | < 9.8.4 | - |
cpe:2.3:a:cisco:cisco_adaptive_security_appliance_(asa)_software:*:*:*:*:*:*:*:*
|
| Cisco | Cisco Firepower Threat Defense (FTD) Software | - | < 6.2.3.12 | - |
cpe:2.3:a:cisco:cisco_firepower_threat_defense_(ftd)_software:*:*:*:*:*:*:*:*
|
| cisco | adaptive_security_appliance_device_manager | * | - | - |
cpe:2.3:a:cisco:adaptive_security_appliance_device_manager:*:*:*:*:*:*:*:*
|
| cisco | firepower_threat_defense | * | - | - |
cpe:2.3:a:cisco:firepower_threat_defense:*:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
CVSS评分详情
3.0 (cna)
MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2019-1715 |
2025-11-11 15:20:08 | 2025-11-11 07:35:38 |
| NVD | nvd_CVE-2019-1715 |
2025-11-11 14:56:22 | 2025-11-11 07:44:09 |
| CNNVD | cnnvd_CNNVD-201905-042 |
2025-11-11 15:10:12 | 2025-11-11 07:54:29 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 其他
- cnnvd_id: 未提取 -> CNNVD-201905-042
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- data_sources: ['cve'] -> ['cve', 'nvd']