CVE-2004-0607

5 documents5 sources
Severity
10.0CRITICAL
EPSS
3.0%
top 13.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 6
Latest updateMay 3

Description

The eay_check_x509cert function in KAME Racoon successfully verifies certificates even when OpenSSL validation fails, which could allow remote attackers to bypass authentication.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages3 packages

NVDkame/racoon4 versions+3
NVDipsec-tools/ipsec-tools8 versions+7

Also affects: Enterprise Linux 3.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-5438-wf9c-p7cg: The eay_check_x509cert function in KAME Racoon successfully verifies certificates even when OpenSSL validation fails, which could allow remote attacke2022-05-03
CVEList
CVE-2004-0607: The eay_check_x509cert function in KAME Racoon successfully verifies certificates even when OpenSSL validation fails, which could allow remote attacke2004-06-30

📋Vendor Advisories

1
Red Hat
security flaw2004-06-15

💬Community

1
Bugzilla
CVE-2004-0607 security flaw2018-08-16
CVE-2004-0607 (CRITICAL CVSS 10) | The eay_check_x509cert function in | cvebase.io