CVE-2023-20107 is a critical vulnerability in the deterministic random bit generator (DRBG) of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software on specific ASA 5506-X, 5508-X, and 5516-X firewall models. This flaw stems from insufficient entropy during cryptographic key generation, allowing an unauthenticated, remote attacker to cause cryptographic collisions. The vulnerability carries a CVSS score of 7.5 (High), indicating a low attack complexity and no user interaction required, with the potential for attackers to discover private keys, impersonate devices, or decrypt traffic. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant media coverage, though it has garnered some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 9.12.1CPE matchmatch criteria | cpe:2.3:a:cisco:adaptive_security_appliance:*:*:*:*:*:*:*:* | ||
< 6.4.0CPE matchmatch criteria | cpe:2.3:a:cisco:firepower_threat_defense:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.