Medium
CVSS 6.4
Overview
Cisco PIX Firewall 6.0.3 and earlier, and 6.1.x to 6.1.3, do not delete the duplicate ISAKMP SAs for a user's VPN session, which allows local users to hijack a session via a man-in-the-middle attack.
Cisco PIX Firewall 6.0.3 and earlier, and 6.1.x to 6.1.3, do not delete the dupl...
Cisco PIX Firewall 6.0.3 and earlier, and 6.1.x to 6.1.3, do not delete the duplicate ISAKMP SAs for a user's VPN session, which allows local users to hijack a session via a man-in-the-middle attack.
This vulnerability is rated 🟡 MEDIUM.
Recommended actions: