Buffer overflow in the Internet Key Exchange version 1 (IKEv1) implementation in Symantec Dynamic VPN Services, as used in Enterprise Firewall, Gateway Security, and Firewall /VPN Appliance products, allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1.
2005-11-23T00:03:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | symantec | enterprise_firewall | 8.0 | Yes |
Application | symantec | enterprise_firewall | 8.0 | Yes |
Hardware | symantec | firewall_vpn_appliance_100 | * | Yes |
Hardware | symantec | firewall_vpn_appliance_200 | * | Yes |
Hardware | symantec | gateway_security_300 | 2.0 | Yes |
Hardware | symantec | gateway_security_400 | 2.0 | Yes |
Hardware | symantec | gateway_security_5000_series | 3.0 | Yes |
Hardware | symantec | gateway_security_5100 | * | Yes |
Hardware | symantec | gateway_security_5300 | 1.0 | Yes |
Hardware | symantec | gateway_security_5310 | 1.0 | Yes |
Hardware | symantec | gateway_security_5400 | 2.0.1 | Yes |