Lucene search

K
cve[email protected]CVE-2005-2359
HistoryAug 05, 2005 - 4:00 a.m.

CVE-2005-2359

2005-08-0504:00:00
web.nvd.nist.gov
19
aes-xcbc-mac
ipsec
freebsd
remote attackers
spoofing
cve-2005-2359
nvd

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

6.7 Medium

AI Score

Confidence

Low

0.011 Low

EPSS

Percentile

84.3%

The AES-XCBC-MAC algorithm in IPsec in FreeBSD 5.3 and 5.4, when used for authentication without other encryption, uses a constant key instead of the one that was assigned by the system administrator, which can allow remote attackers to spoof packets to establish an IPsec session.

Affected configurations

NVD
Node
freebsdfreebsdMatch5.3
OR
freebsdfreebsdMatch5.4

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

6.7 Medium

AI Score

Confidence

Low

0.011 Low

EPSS

Percentile

84.3%