Lucene search

K
nvd[email protected]NVD:CVE-2004-2621
HistoryDec 31, 2004 - 5:00 a.m.

CVE-2004-2621

2004-12-3105:00:00
web.nvd.nist.gov
3

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:P/I:P/A:N

AI Score

6.6

Confidence

High

EPSS

0.006

Percentile

79.4%

Nortel Contivity VPN Client 2.1.7, 3.00, 3.01, 4.91, and 5.01, when opening a VPN tunnel, does not check the gateway certificate until after a dialog box has been displayed to the user, which creates a race condition that allows remote attackers to perform a man-in-the-middle (MITM) attack.

Affected configurations

Nvd
Node
nortelcontivityMatch2.1.7
OR
nortelcontivityMatch3.00
OR
nortelcontivityMatch3.01
OR
nortelcontivityMatch4.91
OR
nortelcontivityMatch5.01
VendorProductVersionCPE
nortelcontivity2.1.7cpe:2.3:h:nortel:contivity:2.1.7:*:*:*:*:*:*:*
nortelcontivity3.00cpe:2.3:h:nortel:contivity:3.00:*:*:*:*:*:*:*
nortelcontivity3.01cpe:2.3:h:nortel:contivity:3.01:*:*:*:*:*:*:*
nortelcontivity4.91cpe:2.3:h:nortel:contivity:4.91:*:*:*:*:*:*:*
nortelcontivity5.01cpe:2.3:h:nortel:contivity:5.01:*:*:*:*:*:*:*

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:P/I:P/A:N

AI Score

6.6

Confidence

High

EPSS

0.006

Percentile

79.4%

Related for NVD:CVE-2004-2621