CVE-2005-3669
published 2005-11-18CVE-2005-3669: Multiple unspecified vulnerabilities in the Internet Key Exchange version 1 (IKEv1) implementation in multiple Cisco products allow remote attackers to cause a…
PriorityP418medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
5.14%
91.5th percentile
Multiple unspecified vulnerabilities in the Internet Key Exchange version 1 (IKEv1) implementation in multiple Cisco products allow remote attackers to cause a denial of service (device reset) via certain malformed IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details in the Cisco advisory, it is unclear which of CVE-2005-3666, CVE-2005-3667, and/or CVE-2005-3668 this issue applies to.
Affected
136 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | adaptive_security_appliance_software | — | — |
| cisco | firewall_services_module | — | — |
| cisco | firewall_services_module | — | — |
| cisco | firewall_services_module | — | — |
| cisco | firewall_services_module | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9rhg-v3xc-rfjw: Multiple unspecified vulnerabilities in the Internet Key Exchange version 1 (IKEv1) implementation in multiple Cisco products allow remote attackers t
ghsa_unreviewed·2022-05-01·CVSS 10.0
CVE-2005-3669 [CRITICAL] GHSA-9rhg-v3xc-rfjw: Multiple unspecified vulnerabilities in the Internet Key Exchange version 1 (IKEv1) implementation in multiple Cisco products allow remote attackers t
Multiple unspecified vulnerabilities in the Internet Key Exchange version 1 (IKEv1) implementation in multiple Cisco products allow remote attackers to cause a denial of service (device reset) via certain malformed IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details in the Cisco advisory, it is unclear which of CVE-2005-3666, CVE-2005-3667, and/or CVE-2005-3668 this issue applies to.
Cisco
Multiple Vulnerabilities Found by PROTOS IPSec Test Suite
vendor_cisco·2005-11-14
CVE-2005-3666 CWE-399 Multiple Vulnerabilities Found by PROTOS IPSec Test Suite
Multiple Vulnerabilities Found by PROTOS IPSec Test Suite
Multiple Cisco products contain vulnerabilities in the processing of
IPSec IKE (Internet Key Exchange) messages. These vulnerabilities were
identified by the University of Oulu Secure Programming Group (OUSPG) "PROTOS"
Test Suite for IPSec and can be repeatedly exploited to produce a denial of
service.
Cisco has made free software available to address this vulnerability
for affected customers. Prior to deploying software, customers should consult
their maintenance provider or check the software for feature set compatibility
and known issues specific to their environment.
This advisory is posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20051114-ipsec.
Cisco
Multiple Vulnerabilities Found by PROTOS IPSec Test Suite
vendor_cisco
CVE-2005-3669 Multiple Vulnerabilities Found by PROTOS IPSec Test Suite
CVE-2005-3669: Multiple Vulnerabilities Found by PROTOS IPSec Test Suite
Multiple Cisco products contain vulnerabilities in the processing of IPSec IKE (Internet Key Exchange) messages. These vulnerabilities were identified by the University of Oulu Secure Programming Group (OUSPG) "PROTOS" Test Suite for IPSec and can be repeatedly exploited to produce a denial of service. Cisco has made free software available to address this vulnerability for affected customers. Prior to deploying software, customers should consult their maintenance provider or check the software for feature set compatibility and known issues specific to their environment. This advisory is posted at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20051114-ipsec .
CWE: CWE-399, CWE-
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://jvn.jp/niscc/NISCC-273756/index.htmlhttp://secunia.com/advisories/17553http://securitytracker.com/id?1015198http://securitytracker.com/id?1015199http://securitytracker.com/id?1015200http://securitytracker.com/id?1015201http://securitytracker.com/id?1015202http://www.cisco.com/warp/public/707/cisco-sa-20051114-ipsec.shtmlhttp://www.ee.oulu.fi/research/ouspg/protos/testing/c09/isakmp/http://www.kb.cert.org/vuls/id/226364http://www.niscc.gov.uk/niscc/docs/br-20051114-01013.html?lang=enhttp://www.securityfocus.com/bid/15401https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5226http://jvn.jp/niscc/NISCC-273756/index.htmlhttp://secunia.com/advisories/17553http://securitytracker.com/id?1015198http://securitytracker.com/id?1015199http://securitytracker.com/id?1015200http://securitytracker.com/id?1015201http://securitytracker.com/id?1015202http://www.cisco.com/warp/public/707/cisco-sa-20051114-ipsec.shtmlhttp://www.ee.oulu.fi/research/ouspg/protos/testing/c09/isakmp/http://www.kb.cert.org/vuls/id/226364http://www.niscc.gov.uk/niscc/docs/br-20051114-01013.html?lang=enhttp://www.securityfocus.com/bid/15401https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5226
2005-11-18
Published