PT-2002-2934 · Openbsd · Isakmpd+1
Published
2002-12-31
·
Updated
2017-07-29
·
CVE-2002-2222
CVSS v2.0
5.1
Medium
| Vector | AV:N/AC:H/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
isakmpd versions prior to 20020403 1
OpenBSD version 3.1
Description:
The issue allows remote attackers to cause a denial of service by sending Internet Key Exchange (IKE) payloads out of sequence. This is due to a problem in the isakmpd/message.c file.
Recommendations:
For isakmpd versions prior to 20020403 1, update to version 20020403 1 or later.
For OpenBSD version 3.1, consider upgrading to a later version of OpenBSD that may include fixes for this issue.
As a temporary workaround, consider restricting access to the IKE protocol to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openbsd
Isakmpd