Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2005-4465


The Internet Key Exchange version 1 (IKEv1) implementation in NEC UNIVERGE IX1000, IX2000, and IX3000 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details in the advisory, it is unclear which of CVE-2005-3666, CVE-2005-3667, and/or CVE-2005-3668 this issue applies to.


Published

2005-12-22T00:03:00.000

Last Modified

2025-04-03T01:03:51.193

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

6.4

Weaknesses
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Hardware nec univerge ix1010 Yes
Hardware nec univerge ix1011 Yes
Hardware nec univerge ix1020 Yes
Hardware nec univerge ix1050 Yes
Hardware nec univerge ix2003 Yes
Hardware nec univerge ix2004 Yes
Hardware nec univerge ix2010 Yes
Hardware nec univerge ix2010 Yes
Hardware nec univerge ix2010 Yes
Hardware nec univerge ix2015 Yes
Hardware nec univerge ix2015 Yes
Hardware nec univerge ix3010 Yes

References