CVE-2023-20107General(cisco / adaptive_security_appliance)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in the deterministic random bit generator (DRBG), also known as pseudorandom number generator (PRNG), in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software for Cisco ASA 5506-X, ASA 5508-X, and ASA 5516-X Firewalls could allow an unauthenticated, remote attacker to cause a cryptographic collision, enabling the attacker to discover the private key of an affected device. This vulnerability is due to insufficient entropy in the DRBG for the affected hardware platforms when generating cryptographic keys. An attacker could exploit this vulnerability by generating a large number of cryptographic keys on an affected device and looking for collisions with target devices. A successful exploit could allow the attacker to impersonate an affected target device or to decrypt traffic secured by an affected key that is sent to or from an affected target device.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-332CWE-331

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • adaptive_security_appliance
  • asa_5506-x
  • asa_5506h-x
  • asa_5506w-x

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • General: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
adaptive_security_applianceasa_5506-xasa_5506h-xasa_5506w-xasa_5508-xasa_5516-xsecure_firewall_threat_defense

1 version affected across 7 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-08: 108-08
Signal classification1 categories
General
1100.0%
Referenced assets2 URLs
Full discourse1 post
  • Francois Garillot@huitseeker
    General

    • buying a Cisco ASA/Firepower enterprise firewall https://nvd.nist.gov/vuln/detail/CVE-2023-20107 • letting a Siemens building controller generate its HTTPS certificate https://nvd.nist.gov/vuln/detail/CVE-2016-9154 6/13

    Post summary

    The post lists two CVEs without any additional context or actionable information.

    11021177
    2.4K followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
Appciscoadaptive_security_appliance---
HWciscoasa_5506-x---
HWciscoasa_5506h-x---
HWciscoasa_5506w-x---
HWciscoasa_5508-x---
HWciscoasa_5516-x---
Appciscosecure_firewall_threat_defense---

Explore more