Lucene search

K
cveCertccCVE-2018-5389
HistorySep 06, 2018 - 9:29 p.m.

CVE-2018-5389

2018-09-0621:29:00
CWE-521
certcc
web.nvd.nist.gov
111
cve
2018
5389
internet key exchange
ike
vulnerability
offline attacks
dictionary attacks
brute force attacks
cross-protocol authentication
psk authentication

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

5.6

Confidence

High

EPSS

0.003

Percentile

70.1%

The Internet Key Exchange v1 main mode is vulnerable to offline dictionary or brute force attacks. Reusing a key pair across different versions and modes of IKE could lead to cross-protocol authentication bypasses. It is well known, that the aggressive mode of IKEv1 PSK is vulnerable to offline dictionary or brute force attacks. For the main mode, however, only an online attack against PSK authentication was thought to be feasible. This vulnerability could allow an attacker to recover a weak Pre-Shared Key or enable the impersonation of a victim host or network.

Affected configurations

Nvd
Node
ietfinternet_key_exchangeMatch1.0
VendorProductVersionCPE
ietfinternet_key_exchange1.0cpe:2.3:a:ietf:internet_key_exchange:1.0:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "strongSwan",
    "product": "Strongswan",
    "versions": [
      {
        "status": "affected",
        "version": "5.5.1"
      }
    ]
  }
]

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

5.6

Confidence

High

EPSS

0.003

Percentile

70.1%