Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2009-1574

Severity
5.0MEDIUM
EPSS
13.5%
top 5.79%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedMay 6
Latest updateMay 2

Description

racoon/isakmp_frag.c in ipsec-tools before 0.7.2 allows remote attackers to cause a denial of service (crash) via crafted fragmented packets without a payload, which triggers a NULL pointer dereference.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-x442-849f-mv4r: racoon/isakmp_frag2022-05-02
CVEList
CVE-2009-1574: racoon/isakmp_frag2009-05-06

💥Exploits & PoCs

1
Exploit-DB
IPsec-Tools < 0.7.2 (racoon frag-isakmp) - Multiple Remote Denial of Service Vulnerabilities (PoC)2009-05-13

📋Vendor Advisories

2
Ubuntu
ipsec-tools vulnerabilities2009-06-09
Red Hat
ipsec-tools: racoon NULL dereference in fragmentation code2009-04-22

💬Community

1
Bugzilla
CVE-2009-1574 ipsec-tools: racoon NULL dereference in fragmentation code2009-04-28