CVE-2002-1623
Summary
| CVE | CVE-2002-1623 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2002-12-31 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | The design of the Internet Key Exchange (IKE) protocol, when using Aggressive Mode for shared secret authentication, does not encrypt initiator or responder identities during negotiation, which may allow remote attackers to determine valid usernames by (1) monitoring responses before the password is supplied or (2) sniffing, as originally reported for FireWall-1 SecuRemote. |
Risk And Classification
Primary CVSS: v2.0 5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:N/A:N
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Checkpoint | Vpn-1 Firewall-1 | 4.0 | All | All | All |
| Application | Checkpoint | Vpn-1 Firewall-1 | 4.1 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| NTA in the news | af854a3a-2127-422b-91ae-364da2661108 | www.nta-monitor.com | |
| [Full-Disclosure] Mailing List Charter | af854a3a-2127-422b-91ae-364da2661108 | lists.grok.org.uk | |
| 'RE: SecuRemote usernames can be guessed or sniffed using IKE' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| 'Checkpoint FW-1 VPN Security Flaw (updated)' - SecuriTeam | af854a3a-2127-422b-91ae-364da2661108 | www.securiteam.com | Exploit |
| SecurityFocus HOME Mailing List: BugTraq | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit |
| 'RE: SecuRemote usernames can be guessed or sniffed using IKE exchange' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| CERT/CC Vulnerability Note VU#886601 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| Check Point Software Technologies: Alerts - IKE Aggressive Mode | af854a3a-2127-422b-91ae-364da2661108 | www.checkpoint.com | |
| Sorry, the content you are trying to view does not exist. If you feel this message is in error, please email the webmaster. | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.