Vulnerability CVE-2006-0718


Published: 2006-02-15   Modified: 2012-02-12

Description:
The Internet Key Exchange version 1 (IKEv1) implementation in Avaya VSU 100, 2000, 7500, 10000, and CSU 5000, when running IPSec, allows remote attackers to cause a denial of service (crash) via certain IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details in the advisory, it is unclear which of CVE-2005-3666, CVE-2005-3667, and/or CVE-2005-3668 this issue applies to.

CVSS2 => (AV:N/AC:L/Au:N/C:N/I:N/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
None
Partial
Affected software
Avaya -> Vsu 100 
Avaya -> Vsu 10000 
Avaya -> Vsu 2000 
Avaya -> Vsu 7500 
Avaya -> Csu 5000 

 References:
http://www.kb.cert.org/vuls/id/226364
http://support.avaya.com/elmodocs2/security/ASA-2006-043.htm
http://www.securityfocus.com/bid/16613
http://secunia.com/advisories/18836

Copyright 2024, cxsecurity.com

 

Back to Top