cbcvebase.
CVE-2002-0666
published 2002-11-04

CVE-2002-0666: IPSEC implementations including (1) FreeS/WAN and (2) KAME do not properly calculate the length of authentication data, which allows remote attackers to cause…

PriorityP419medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.47%
82.7th percentile
IPSEC implementations including (1) FreeS/WAN and (2) KAME do not properly calculate the length of authentication data, which allows remote attackers to cause a denial of service (kernel panic) via spoofed, short Encapsulating Security Payload (ESP) packets, which result in integer signedness errors.

Affected

18 ranges
VendorProductVersion rangeFixed in
applemac_os_x
applemac_os_x_server
freebsdfreebsd
frees_wanfrees_wan
frees_wanfrees_wan
frees_wanfrees_wan
frees_wanfrees_wan
frees_wanfrees_wan
frees_wanfrees_wan
frees_wanfrees_wan
global_technology_associatesgnat_box_firmware
global_technology_associatesgnat_box_firmware
global_technology_associatesgnat_box_firmware
netbsdnetbsd
netbsdnetbsd
netbsdnetbsd
netbsdnetbsd
netbsdnetbsd
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.