PT-2005-3274 · Freebsd · Freebsd

Publicado

2005-08-01

·

Atualizado

2017-07-11

·

CVE-2005-2359

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions FreeBSD versions 5.3 through 5.4
Description The issue concerns the AES-XCBC-MAC algorithm in IPsec, which is used for authentication. When this algorithm is used without other encryption, it uses a constant key instead of the one assigned by the system administrator. This can allow remote attackers to spoof packets and establish an IPsec session.
Recommendations For FreeBSD versions 5.3 through 5.4, consider using additional encryption to secure IPsec sessions until a fix is available. As a temporary workaround, restrict access to IPsec sessions to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-2359

Produtos afetados

Freebsd