CVE Vulnerabilities

CVE-2005-2359

Published: Aug 05, 2005 | Modified: Jul 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

The AES-XCBC-MAC algorithm in IPsec in FreeBSD 5.3 and 5.4, when used for authentication without other encryption, uses a constant key instead of the one that was assigned by the system administrator, which can allow remote attackers to spoof packets to establish an IPsec session.

Affected Software

Name Vendor Start Version End Version
Freebsd Freebsd 5.3 (including) 5.3 (including)
Freebsd Freebsd 5.4 (including) 5.4 (including)
Kfreebsd-5 Ubuntu dapper *
Kfreebsd-5 Ubuntu devel *
Kfreebsd-5 Ubuntu edgy *
Kfreebsd-5 Ubuntu feisty *

References