CVE-2004-0607
5 documents5 sources
Severity
10.0CRITICAL
EPSS
3.0%
top 13.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 6
Latest updateMay 3
Description
The eay_check_x509cert function in KAME Racoon successfully verifies certificates even when OpenSSL validation fails, which could allow remote attackers to bypass authentication.
CVSS vector
AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0
Affected Packages3 packages
Also affects: Enterprise Linux 3.0
Patches
🔴Vulnerability Details
2GHSA▶
GHSA-5438-wf9c-p7cg: The eay_check_x509cert function in KAME Racoon successfully verifies certificates even when OpenSSL validation fails, which could allow remote attacke↗2022-05-03
CVEList▶
CVE-2004-0607: The eay_check_x509cert function in KAME Racoon successfully verifies certificates even when OpenSSL validation fails, which could allow remote attacke↗2004-06-30