PT-2001-1595 · Sonicwall · Sonicwall Soho+1
Published
2001-05-24
·
Updated
2017-12-19
·
CVE-2001-0376
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
SonicWALL Tele2 and SOHO firewalls version 6.0.0.0
Description
The issue concerns the use of IPSEC with IKE pre-shared keys in SonicWALL Tele2 and SOHO firewalls. These firewalls do not support the full 128 byte IKE pre-shared keys as intended, instead only supporting 48 byte keys. This limitation allows a remote attacker to perform a brute force attack on the pre-shared keys with significantly less resources than would be required if the full 128 byte keys were used.
Recommendations
For SonicWALL Tele2 and SOHO firewalls version 6.0.0.0, consider using alternative security measures to mitigate the risk of brute force attacks on the pre-shared keys, such as implementing additional authentication mechanisms or restricting access to the firewall. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sonicwall Soho
Sonicwall Tele2