Vulnerability CVE-2005-3669


Published: 2005-11-18   Modified: 2012-02-12

Description:
Multiple unspecified vulnerabilities in the Internet Key Exchange version 1 (IKEv1) implementation in multiple Cisco products allow remote attackers to cause a denial of service (device reset) via certain malformed IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details in the Cisco advisory, it is unclear which of CVE-2005-3666, CVE-2005-3667, and/or CVE-2005-3668 this issue applies to.

Type:

CWE-Other

CVSS2 => (AV:N/AC:L/Au:N/C:N/I:N/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
None
Partial
Affected software
Cisco -> Pix firewall 
Cisco -> Firewall services module 
Cisco -> Mds 9000 
Cisco -> Adaptive security appliance 
Cisco -> IOS 
Cisco -> Vpn 3000 concentrator 
Cisco -> Adaptive security appliance software 
Cisco -> Mds 9000 san-os 
Cisco -> Pix firewall software 
Cisco -> Vpn 3000 concentrator series software 

 References:
http://jvn.jp/niscc/NISCC-273756/index.html
http://securitytracker.com/id?1015198
http://securitytracker.com/id?1015199
http://securitytracker.com/id?1015200
http://securitytracker.com/id?1015201
http://securitytracker.com/id?1015202
http://www.cisco.com/warp/public/707/cisco-sa-20051114-ipsec.shtml
http://www.ee.oulu.fi/research/ouspg/protos/testing/c09/isakmp/
http://www.kb.cert.org/vuls/id/226364
http://www.niscc.gov.uk/niscc/docs/br-20051114-01013.html?lang=en
http://www.securityfocus.com/bid/15401
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5226

Copyright 2024, cxsecurity.com

 

Back to Top