CVE Vulnerabilities

CVE-2004-2621

Published: Dec 31, 2004 | Modified: Jul 20, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:H/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Nortel Contivity VPN Client 2.1.7, 3.00, 3.01, 4.91, and 5.01, when opening a VPN tunnel, does not check the gateway certificate until after a dialog box has been displayed to the user, which creates a race condition that allows remote attackers to perform a man-in-the-middle (MITM) attack.

Affected Software

Name Vendor Start Version End Version
Contivity Nortel 2.1.7 (including) 2.1.7 (including)
Contivity Nortel 3.00 (including) 3.00 (including)
Contivity Nortel 3.01 (including) 3.01 (including)
Contivity Nortel 4.91 (including) 4.91 (including)
Contivity Nortel 5.01 (including) 5.01 (including)

References