Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2005-3671


The Internet Key Exchange version 1 (IKEv1) implementation in Openswan 2 (openswan-2) before 2.4.4, and freeswan in SUSE LINUX 9.1 before 2.04_1.5.4-1.23, allow remote attackers to cause a denial of service via (1) a crafted packet using 3DES with an invalid key length, or (2) unspecified inputs when Aggressive Mode is enabled and the PSK is known, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1.


Published

2005-11-18T21:03:00.000

Last Modified

2025-04-03T01:03:51.193

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 7.8 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:N/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: COMPLETE
Exploitability Score

10.0

Impact Score

6.9

Weaknesses
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application frees_wan frees_wan 2.04 Yes
Application openswan openswan 2.1.1 Yes
Application openswan openswan 2.1.2 Yes
Application openswan openswan 2.1.4 Yes
Application openswan openswan 2.1.5 Yes
Application openswan openswan 2.1.6 Yes
Application openswan openswan 2.2 Yes
Application openswan openswan 2.3 Yes
Application xelerance openswan 2.4.0 Yes

References