CVE-2005-3669

CWE-3994 documents4 sources
Severity
5.0MEDIUM
EPSS
9.5%
top 7.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 18
Latest updateMay 1

Description

Multiple unspecified vulnerabilities in the Internet Key Exchange version 1 (IKEv1) implementation in multiple Cisco products allow remote attackers to cause a denial of service (device reset) via certain malformed IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details in the Cisco advisory, it is unclear which of CVE-2005-3666, CVE-2005-3667, and/or CVE-2005-3668 this issue applies to.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages7 packages

NVDcisco/ios37 versions+36
NVDcisco/pix_firewall6.2.2_.111, 6.2.3_\(110\), 6.3.3_\(133\)+2
NVDcisco/mds_9000_san-os1.3\(3.33\), 1.3\(4a\), 2.0\(0.86\)+2
NVDcisco/pix_firewall_software55 versions+54

🔴Vulnerability Details

2
GHSA
GHSA-9rhg-v3xc-rfjw: Multiple unspecified vulnerabilities in the Internet Key Exchange version 1 (IKEv1) implementation in multiple Cisco products allow remote attackers t2022-05-01
CVEList
CVE-2005-3669: Multiple unspecified vulnerabilities in the Internet Key Exchange version 1 (IKEv1) implementation in multiple Cisco products allow remote attackers t2005-11-18

📋Vendor Advisories

1
Cisco
Multiple Vulnerabilities Found by PROTOS IPSec Test Suite2005-11-14