CVE Vulnerabilities

CVE-2008-1198

Published: Mar 06, 2008 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.1 HIGH
AV:N/AC:M/Au:N/C:C/I:N/A:N
RedHat/V2
2.6 LOW
AV:N/AC:H/Au:N/C:P/I:N/A:N
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

The default IPSec ifup script in Red Hat Enterprise Linux 3 through 5 configures racoon to use aggressive IKE mode instead of main IKE mode, which makes it easier for remote attackers to conduct brute force attacks by sniffing an unencrypted preshared key (PSK) hash.

Affected Software

NameVendorStart VersionEnd Version
Enterprise_linuxRedhat4.0 (including)4.0 (including)
Enterprise_linuxRedhat3.0 (including)3.0 (including)
Enterprise_linuxRedhat5.0 (including)5.0 (including)
Red Hat Enterprise Linux 5RedHatinitscripts-0:8.45.42-1.el5*

References