Lucene search

K
cve[email protected]CVE-2007-3805
HistoryJul 16, 2007 - 11:30 p.m.

CVE-2007-3805

2007-07-1623:30:00
CWE-310
web.nvd.nist.gov
24
cve-2007-3805
clavister coreplus
ike
certificate validation
denial of service

5.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:H/Au:N/C:N/I:N/A:C

6.7 Medium

AI Score

Confidence

High

0.008 Low

EPSS

Percentile

81.5%

The IKE implementation in Clavister CorePlus before 8.80.03, and 8.80.00, does not properly validate certificates during IKE negotiation, which allows remote attackers to cause a denial of service (gateway stop) via certain certificates.

Affected configurations

NVD
Node
clavisterclavister_coreplusRange8.80.03
OR
clavisterclavister_coreplusMatch8.81.00

5.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:H/Au:N/C:N/I:N/A:C

6.7 Medium

AI Score

Confidence

High

0.008 Low

EPSS

Percentile

81.5%

Related for CVE-2007-3805