CVE-2005-3670
published 2005-11-18CVE-2005-3670: Multiple unspecified vulnerabilities in the Internet Key Exchange version 1 (IKEv1) implementation in HP HP-UX B.11.00, B.11.11, and B.11.23 running IPSec, HP…
PriorityP334high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
9.12%
94.7th percentile
Multiple unspecified vulnerabilities in the Internet Key Exchange version 1 (IKEv1) implementation in HP HP-UX B.11.00, B.11.11, and B.11.23 running IPSec, HP Jetdirect 635n IPv6/IPsec Print Server, and HP Tru64 UNIX 5.1B-3 and 5.1B-2/PK4, allow remote attackers to cause a denial of service via certain IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details in the HP advisory, it is unclear which of CVE-2005-3666, CVE-2005-3667, and/or CVE-2005-3668 this issue applies to.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| hp | hp-ux | — | — |
| hp | hp-ux | — | — |
| hp | hp-ux | — | — |
| hp | tru64 | — | — |
| hp | tru64 | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Multiple Vulnerabilities Found by PROTOS IPSec Test Suite
vendor_cisco·2005-11-14
CVE-2005-3666 CWE-399 Multiple Vulnerabilities Found by PROTOS IPSec Test Suite
Multiple Vulnerabilities Found by PROTOS IPSec Test Suite
Multiple Cisco products contain vulnerabilities in the processing of
IPSec IKE (Internet Key Exchange) messages. These vulnerabilities were
identified by the University of Oulu Secure Programming Group (OUSPG) "PROTOS"
Test Suite for IPSec and can be repeatedly exploited to produce a denial of
service.
Cisco has made free software available to address this vulnerability
for affected customers. Prior to deploying software, customers should consult
their maintenance provider or check the software for feature set compatibility
and known issues specific to their environment.
This advisory is posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20051114-ipsec.
Cisco
Multiple Vulnerabilities Found by PROTOS IPSec Test Suite
vendor_cisco
CVE-2005-3670 Multiple Vulnerabilities Found by PROTOS IPSec Test Suite
CVE-2005-3670: Multiple Vulnerabilities Found by PROTOS IPSec Test Suite
Multiple Cisco products contain vulnerabilities in the processing of IPSec IKE (Internet Key Exchange) messages. These vulnerabilities were identified by the University of Oulu Secure Programming Group (OUSPG) "PROTOS" Test Suite for IPSec and can be repeatedly exploited to produce a denial of service. Cisco has made free software available to address this vulnerability for affected customers. Prior to deploying software, customers should consult their maintenance provider or check the software for feature set compatibility and known issues specific to their environment. This advisory is posted at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20051114-ipsec .
CWE: CWE-399, CWE-
GHSA
GHSA-4rm2-h745-5rf8: Multiple unspecified vulnerabilities in the Internet Key Exchange version 1 (IKEv1) implementation in HP HP-UX B
ghsa_unreviewed·2022-05-01·CVSS 10.0
CVE-2005-3670 [CRITICAL] GHSA-4rm2-h745-5rf8: Multiple unspecified vulnerabilities in the Internet Key Exchange version 1 (IKEv1) implementation in HP HP-UX B
Multiple unspecified vulnerabilities in the Internet Key Exchange version 1 (IKEv1) implementation in HP HP-UX B.11.00, B.11.11, and B.11.23 running IPSec, HP Jetdirect 635n IPv6/IPsec Print Server, and HP Tru64 UNIX 5.1B-3 and 5.1B-2/PK4, allow remote attackers to cause a denial of service via certain IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details in the HP advisory, it is unclear which of CVE-2005-3666, CVE-2005-3667, and/or CVE-2005-3668 this issue applies to.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://jvn.jp/niscc/NISCC-273756/index.htmlhttp://secunia.com/advisories/17598http://secunia.com/advisories/19174http://securitytracker.com/id?1015227http://securitytracker.com/id?1015229http://securitytracker.com/id?1015727http://www.ee.oulu.fi/research/ouspg/protos/testing/c09/isakmp/http://www.kb.cert.org/vuls/id/226364http://www.kb.cert.org/vuls/id/MIMG-6J6QS4http://www.niscc.gov.uk/niscc/docs/re-20051114-01014.pdf?lang=enhttp://www.securityfocus.com/bid/15471http://www.securityfocus.com/bid/15474http://www.securityfocus.com/bid/17030http://www.vupen.com/english/advisories/2005/2462http://www.vupen.com/english/advisories/2006/0880http://www2.itrc.hp.com/service/cki/docDisplay.do?admit=-1335382922+1141762289787+28353475&docId=c00602119https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5642http://jvn.jp/niscc/NISCC-273756/index.htmlhttp://secunia.com/advisories/17598http://secunia.com/advisories/19174http://securitytracker.com/id?1015227http://securitytracker.com/id?1015229http://securitytracker.com/id?1015727http://www.ee.oulu.fi/research/ouspg/protos/testing/c09/isakmp/http://www.kb.cert.org/vuls/id/226364http://www.kb.cert.org/vuls/id/MIMG-6J6QS4http://www.niscc.gov.uk/niscc/docs/re-20051114-01014.pdf?lang=enhttp://www.securityfocus.com/bid/15471http://www.securityfocus.com/bid/15474http://www.securityfocus.com/bid/17030http://www.vupen.com/english/advisories/2005/2462http://www.vupen.com/english/advisories/2006/0880http://www2.itrc.hp.com/service/cki/docDisplay.do?admit=-1335382922+1141762289787+28353475&docId=c00602119https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5642
2005-11-18
Published