PT-2005-5615 · Frees/Wan+2 · Frees/Wan+4

Published

1970-01-01

·

Updated

2019-07-29

·

CVE-2005-3671

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions openswan versions prior to 2.4.4 freeswan version prior to 2.04 1.5.4-1.23
Description The issue allows remote attackers to cause a denial of service via crafted packets or unspecified inputs when Aggressive Mode is enabled and the PSK is known. This can be exploited to produce a denial of service. The vulnerability was identified by the University of Oulu Secure Programming Group (OUSPG) "PROTOS" Test Suite for IPSec.
Recommendations For openswan versions prior to 2.4.4, update to version 2.4.4 or later to address the vulnerability. For freeswan version prior to 2.04 1.5.4-1.23, update to version 2.04 1.5.4-1.23 or later to address the vulnerability. As a temporary workaround, consider disabling Aggressive Mode until a patch is available. Restrict access to the affected IPSec IKE implementation to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-04788
BDU:2015-04812
BDU:2015-04813
BDU:2015-09489
CVE-2005-3671

Affected Products

Cisco Asa
Cisco Ios
Cisco Wls
Frees/Wan
Openswan