CVE-2013-1194:CVE-2013-1194 is a vulnerability in the ISAKMP implementation on Cisco Adaptive Security Appliances (ASA) devices that allows remote attackers to enumerate VPN groups.

splash
Back

Description Preview

The ISAKMP implementation on Cisco ASA devices generates different responses for IKE aggressive-mode messages depending on whether invalid VPN groups are specified. This behavior can be exploited by remote attackers to enumerate groups through a series of messages. This vulnerability is identified as Bug ID CSCue73708.

Overview

This vulnerability affects the ISAKMP implementation on Cisco ASA devices, allowing remote attackers to enumerate VPN groups by manipulating IKE aggressive-mode messages. The issue was made public on April 17, 2013, and is assigned CVE-2013-1194.

Remediation

To remediate this vulnerability, Cisco released patches and updates to address the enumeration of VPN groups in the ISAKMP implementation on ASA devices. It is recommended to apply the necessary security updates provided by Cisco to mitigate the risk of exploitation.

References

  1. Cisco Security Advisory: 20130417 Cisco ASA Software VPN Group Enumeration Vulnerability

  2. Bugtraq Advisory: 20130418 TWSL2013-004: Group Name Enumeration Vulnerability in Cisco IKE Implementation

Industry ExposureMost to least
This section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.

  1. Public Administration
    Public Administration
  2. Accommodation & Food Services
    Accommodation & Food Services
  3. Administrative, Support, Waste Management & Remediation Services
    Administrative, Support, Waste Management & Remediation Services
  4. Agriculture, Forestry Fishing & Hunting
    Agriculture, Forestry Fishing & Hunting
  5. Arts, Entertainment & Recreation
    Arts, Entertainment & Recreation
  6. Construction
    Construction
  7. Educational Services
    Educational Services
  8. Finance and Insurance
    Finance and Insurance
  9. Health Care & Social Assistance
    Health Care & Social Assistance
  10. Information
    Information
  11. Management of Companies & Enterprises
    Management of Companies & Enterprises
  12. Manufacturing
    Manufacturing
  13. Mining
    Mining
  14. Other Services (except Public Administration)
    Other Services (except Public Administration)
  15. Professional, Scientific, & Technical Services
    Professional, Scientific, & Technical Services
  16. Real Estate Rental & Leasing
    Real Estate Rental & Leasing
  17. Retail Trade
    Retail Trade
  18. Transportation & Warehousing
    Transportation & Warehousing
  19. Utilities
    Utilities
  20. Wholesale Trade
    Wholesale Trade

Focus on What Matters

  1. See Everything.
  2. Identify True Risk.
  3. Proactively Mitigate Threats.

Let's talk!

background
Armis Vulnerability Intelligence Database