Secgo Software Crypto IP Gateway/Client IKEv1 Traffic Multiple Unspecified Vulnerabilities
BID:15403
Info
Secgo Software Crypto IP Gateway/Client IKEv1 Traffic Multiple Unspecified Vulnerabilities
| Bugtraq ID: | 15403 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 14 2005 12:00AM |
| Updated: | Nov 14 2005 12:00AM |
| Credit: | Discovery is credited to NISCC, CERT-FI, and the Oulu University Secure Programming Group. |
| Vulnerable: |
Secgo Software Crypto IP Gateway 3.2.26 Secgo Software Crypto IP Gateway 3.2 Secgo Software Crypto IP Gateway 3.0.82 Secgo Software Crypto IP Gateway 3.0 Secgo Software Crypto IP Gateway 2.3 Secgo Software Crypto IP Client 3.2.26 Secgo Software Crypto IP Client 3.2 Secgo Software Crypto IP Client 3.1 Secgo Software Crypto IP Client 3.0.82 Secgo Software Crypto IP Client 3.0 Secgo Software Crypto IP Client 2.3 |
| Not Vulnerable: |
Secgo Software Crypto IP Gateway 3.4 Secgo Software Crypto IP Gateway 3.2.28 Secgo Software Crypto IP Gateway 3.0.84 Secgo Software Crypto IP Client 3.4 Secgo Software Crypto IP Client 3.2.28 Secgo Software Crypto IP Client 3.0.84 |
Discussion
Secgo Software Crypto IP Gateway/Client IKEv1 Traffic Multiple Unspecified Vulnerabilities
Secgo Software Crypto IP Gateway and Client are prone to multiple unspecified vulnerabilities in their IKEv1 implementation. The reported issues include buffer overflows and denial of service vulnerabilities.
These issues were discovered with the PROTOS ISAKMP Test Suite and are related to handling of malformed IKEv1 traffic.
Secgo Software Crypto IP Gateway and Client are prone to multiple unspecified vulnerabilities in their IKEv1 implementation. The reported issues include buffer overflows and denial of service vulnerabilities.
These issues were discovered with the PROTOS ISAKMP Test Suite and are related to handling of malformed IKEv1 traffic.
Exploit / POC
Secgo Software Crypto IP Gateway/Client IKEv1 Traffic Multiple Unspecified Vulnerabilities
These issues can be reproduced using the PROTOS ISAKMP Test Suite. It should be noted that the Test Suite may trigger the vulnerabilities but is not designed to exploit the buffer overflow issues to execute arbitrary code.
These issues can be reproduced using the PROTOS ISAKMP Test Suite. It should be noted that the Test Suite may trigger the vulnerabilities but is not designed to exploit the buffer overflow issues to execute arbitrary code.
Solution / Fix
Secgo Software Crypto IP Gateway/Client IKEv1 Traffic Multiple Unspecified Vulnerabilities
Solution:
Secgo Software has released Crypto IP Gateway and Client version 3.4 to address this issue. Users are advised to upgrade.
If an upgrade to 3.4 is not possible or desired, Gateway and Client releases 3.0.84/3.2.28 are not affected by the issues.
Solution:
Secgo Software has released Crypto IP Gateway and Client version 3.4 to address this issue. Users are advised to upgrade.
If an upgrade to 3.4 is not possible or desired, Gateway and Client releases 3.0.84/3.2.28 are not affected by the issues.
References
Secgo Software Crypto IP Gateway/Client IKEv1 Traffic Multiple Unspecified Vulnerabilities
References:
References:
- Multiple Vulnerability Issues in Implementations of ISAKMP Protocol (NISCC)
- Secgo Software Homepage (Secgo Software)
- Vulnerabilities in IKEv1 implementation, CERT-FI: 7710 (Secgo Software)