Multiple Clavister Products IKE Exchange Denial Of Service Vulnerabilities
BID:15560
Info
Multiple Clavister Products IKE Exchange Denial Of Service Vulnerabilities
| Bugtraq ID: | 15560 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2005-3670 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 24 2005 12:00AM |
| Updated: | Nov 24 2005 12:00AM |
| Credit: | Discovery is credited to NISCC, CERT-FI, and the Oulu University Secure Programming Group. |
| Vulnerable: |
Clavister Security Gateway 8.60 .01 RC1 Clavister Security Gateway 8.50 .02 Clavister Security Gateway 8.40 .05 Clavister Firewall 8.30 .01 |
| Not Vulnerable: | |
Discussion
Multiple Clavister Products IKE Exchange Denial Of Service Vulnerabilities
Clavister Firewall and Security Gateway products are prone to denial of service vulnerabilities. These issues are due to security flaws in Clavister's IPSec implementation. These vulnerabilities may be triggered by malformed IKE traffic.
This issue was discovered with the PROTOS ISAKMP Test Suite and is related to the handling of malformed IKEv1 traffic.
Clavister Firewall and Security Gateway products are prone to denial of service vulnerabilities. These issues are due to security flaws in Clavister's IPSec implementation. These vulnerabilities may be triggered by malformed IKE traffic.
This issue was discovered with the PROTOS ISAKMP Test Suite and is related to the handling of malformed IKEv1 traffic.
Exploit / POC
Multiple Clavister Products IKE Exchange Denial Of Service Vulnerabilities
These issues can be reproduced using the PROTOS ISAKMP Test Suite.
These issues can be reproduced using the PROTOS ISAKMP Test Suite.
Solution / Fix
Multiple Clavister Products IKE Exchange Denial Of Service Vulnerabilities
Solution:
The vendor has released an advisory, along with fixes to address these issues. Please see the referenced advisory for further information.
Users of affected packages may obtain fixes through Clavister Client Web.
Solution:
The vendor has released an advisory, along with fixes to address these issues. Please see the referenced advisory for further information.
Users of affected packages may obtain fixes through Clavister Client Web.
References
Multiple Clavister Products IKE Exchange Denial Of Service Vulnerabilities
References:
References:
- Clavister Client Web (Clavister)
- Clavister Home Page (Clavister)
- Clavister Security Advisory: Multiple Vulnerabilities Found in ISAKMP (Clavister)
- Multiple Vulnerability Issues in Implementations of ISAKMP Protocol (NISCC)
- Software updates for ISAKMP vulnerability now available. All Clavister users are (Clavister)