PT-2007-6996 · Ingate · Siparator+1

Published

2007-11-22

·

Updated

2008-11-15

·

CVE-2007-6094

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Ingate Firewall versions prior to 4.6.0 SIParator versions prior to 4.6.0
Description The issue allows remote attackers to cause a denial of service, resulting in a module crash, by exploiting an IPsec Phase 2 proposal that lacks Perfect Forward Secrecy (PFS) in the IPsec module of the VPN component.
Recommendations For Ingate Firewall versions prior to 4.6.0, update to version 4.6.0 or later to resolve the issue. For SIParator versions prior to 4.6.0, update to version 4.6.0 or later to resolve the issue.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-6094

Affected Products

Ingate Firewall
Siparator