CVE-2004-0369
Summary
| CVE | CVE-2004-0369 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2004-12-31 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Buffer overflow in Entrust LibKmp ISAKMP library, as used by Symantec Enterprise Firewall 7.0 through 8.0, Gateway Security 5300 1.0, Gateway Security 5400 2.0, and VelociRaptor 1.5, allows remote attackers to execute arbitrary code via a crafted ISAKMP payload. |
Risk And Classification
Primary CVSS: v2.0 7.5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Entrust | Entrust Libkmp Isakmp Library | All | All | All | All |
| Application | Symantec | Enterprise Firewall | 7.0 | All | solaris | All |
| Application | Symantec | Enterprise Firewall | 7.0.4 | All | solaris | All |
| Application | Symantec | Enterprise Firewall | 7.0.4 | All | windows_2000_nt | All |
| Application | Symantec | Enterprise Firewall | 8.0 | All | solaris | All |
| Application | Symantec | Enterprise Firewall | 8.0 | All | windows_2000_nt | All |
| Hardware | Symantec | Gateway Security 5300 | 1.0 | All | All | All |
| Hardware | Symantec | Gateway Security 5400 | 2.0 | All | All | All |
| Application | Symantec | Velociraptor | 1.5 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Symantec IPsec/ISAKMP VPN Buffer Overflow | af854a3a-2127-422b-91ae-364da2661108 | securityresponse.symantec.com | Vendor Advisory |
| Entrust LibKMP ISAKMP Library Remote IPsec/ISAKMP Buffer Overflow Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| AusCERT - ESB-2004.0538 -- SYM04-012 -- Symantec IPsec/ISAKMP VPN Buffer Overflow | af854a3a-2127-422b-91ae-364da2661108 | www.auscert.org.au | Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| O-206: Entrust LibKmp Library Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.ciac.org | Vendor Advisory |
| xforce.iss.net/xforce/alerts/id/181 | af854a3a-2127-422b-91ae-364da2661108 | xforce.iss.net | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.