Multiple Vendor IKE Implementation Certificate Authenticity Verification Vulnerability
BID:9208
Info
Multiple Vendor IKE Implementation Certificate Authenticity Verification Vulnerability
| Bugtraq ID: | 9208 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 12 2003 12:00AM |
| Updated: | Dec 12 2003 12:00AM |
| Credit: | Discovery has been credited to Thor Lancelot Simon <[email protected]>. |
| Vulnerable: |
Microsoft Windows XP Tablet PC Edition Microsoft Windows XP Professional SP1 Microsoft Windows XP Professional Microsoft Windows XP Media Center Edition Microsoft Windows XP Home SP1 Microsoft Windows XP Home Microsoft Windows XP Embedded SP1 Microsoft Windows XP Embedded Microsoft Windows XP 64-bit Edition Version 2003 Microsoft Windows XP 64-bit Edition SP1 Microsoft Windows XP 64-bit Edition Microsoft Windows 2000 Server SP4 Microsoft Windows 2000 Server SP3 Microsoft Windows 2000 Server SP2 Microsoft Windows 2000 Professional SP4 Microsoft Windows 2000 Professional SP3 Microsoft Windows 2000 Professional SP2 Microsoft Windows 2000 Datacenter Server SP4 Microsoft Windows 2000 Datacenter Server SP3 Microsoft Windows 2000 Datacenter Server SP2 Microsoft Windows 2000 Advanced Server SP4 Microsoft Windows 2000 Advanced Server SP3 Microsoft Windows 2000 Advanced Server SP2 FreeS/WAN FreeS/WAN 1.9.6 FreeS/WAN FreeS/WAN 1.9.5 FreeS/WAN FreeS/WAN 1.9.4 FreeS/WAN FreeS/WAN 1.9.3 FreeS/WAN FreeS/WAN 1.9.2 FreeS/WAN FreeS/WAN 1.9.1 FreeS/WAN FreeS/WAN 1.9 Cisco VPN Client for Windows 4.0.2 C Cisco VPN Client for Windows 4.0.2 A Cisco VPN Client for Windows 3.6.1 Cisco VPN Client for Windows 3.6 (Rel) Cisco VPN Client for Windows 3.6 Cisco VPN Client for Windows 3.5.4 Cisco VPN Client for Windows 3.5.2 B Cisco VPN Client for Windows 3.5.2 Cisco VPN Client for Windows 3.5.1 C Cisco VPN Client for Windows 3.5.1 Cisco VPN Client for Windows 3.1 Cisco VPN Client for Windows 3.0.5 Cisco VPN Client for Windows 3.0 Cisco VPN Client for Windows 2.0 Cisco VPN Client for Solaris 4.0.2 C Cisco VPN Client for Solaris 4.0.2 A Cisco VPN Client for Solaris 3.6.1 Cisco VPN Client for Solaris 3.6 Cisco VPN Client for Solaris 3.5.4 Cisco VPN Client for Solaris 3.5.2 B Cisco VPN Client for Solaris 3.5.2 Cisco VPN Client for Solaris 3.5.1 Cisco VPN Client for Mac OS X 4.0.2 C Cisco VPN Client for Mac OS X 4.0.2 A Cisco VPN Client for Mac OS X 3.6.1 Cisco VPN Client for Mac OS X 3.6 Cisco VPN Client for Mac OS X 3.5.4 Cisco VPN Client for Mac OS X 3.5.2 B Cisco VPN Client for Mac OS X 3.5.2 Cisco VPN Client for Mac OS X 3.5.1 Cisco VPN Client for Linux 3.6.1 Cisco VPN Client for Linux 3.6 Cisco VPN Client for Linux 3.5.4 Cisco VPN Client for Linux 3.5.2 B Cisco VPN Client for Linux 3.5.2 Cisco VPN Client for Linux 3.5.1 Cisco VPN 5000 Client for Solaris 5.2.8 Cisco VPN 5000 Client for Solaris 5.2.7 Cisco VPN 5000 Client for Mac OS 5.2.2 Cisco VPN 5000 Client for Mac OS 5.2.1 Cisco VPN 5000 Client for Mac OS 5.1.2 Cisco VPN 5000 Client for Linux 5.2.7 Cisco VPN 5000 Client for Linux 5.2.6 Cisco VPN 3002 Hardware Client Cisco VPN 3000 Concentrator 4.0.1 Cisco VPN 3000 Concentrator 4.0 .x Cisco VPN 3000 Concentrator 4.0 Cisco VPN 3000 Concentrator 3.6.7 D Cisco VPN 3000 Concentrator 3.6.7 Cisco VPN 3000 Concentrator 3.6.1 Cisco VPN 3000 Concentrator 3.6 Cisco VPN 3000 Concentrator 3.5.5 Cisco VPN 3000 Concentrator 3.5.4 Cisco VPN 3000 Concentrator 3.5.3 Cisco VPN 3000 Concentrator 3.5.2 Cisco VPN 3000 Concentrator 3.5.1 Cisco VPN 3000 Concentrator 3.5 (Rel) Cisco VPN 3000 Concentrator 3.1.4 Cisco VPN 3000 Concentrator 3.1.2 Cisco VPN 3000 Concentrator 3.1.1 Cisco VPN 3000 Concentrator 3.1 (Rel) Cisco VPN 3000 Concentrator 3.1 Cisco VPN 3000 Concentrator 3.0.4 Cisco VPN 3000 Concentrator 3.0.3 (B) Cisco VPN 3000 Concentrator 3.0.3 (A) Cisco VPN 3000 Concentrator 3.0 Cisco VPN 3000 Concentrator 3.0 Cisco VPN 3000 Concentrator 2.5.2 (F) Cisco VPN 3000 Concentrator 2.5.2 (D) Cisco VPN 3000 Concentrator 2.5.2 (C) Cisco VPN 3000 Concentrator 2.5.2 (B) Cisco VPN 3000 Concentrator 2.5.2 (A) Cisco VPN 3000 Concentrator 2.0 Certicom MovianVPN |
| Not Vulnerable: | |
Discussion
Multiple Vendor IKE Implementation Certificate Authenticity Verification Vulnerability
It has been reported that some default IKE implementations may carry out insufficient certificate authenticity verification.
The vulnerability lies in the fact that some implementations fail to thoroughly verify the authenticity of client/server certificates. Allegedly, affected implementations will verify only the Certificate Authority, not the specific certificate owner. As a result, by impersonating a server or client and sending another host a specially formatted certificate with a trusted CA, an attacker may be capable of using this attack to carry out man-in-the-middle attacks against a session carried out between a legitimate client and server.
Although specific vendor product versions affected by this issue are not currently known, the researcher has stated that the following vendors are or may be affected: Microsoft Windows, Cisco, Nortel, FreeS\WAN and Certicom. It should be noted that other vendors/products may be affected as well.
It has been reported that some default IKE implementations may carry out insufficient certificate authenticity verification.
The vulnerability lies in the fact that some implementations fail to thoroughly verify the authenticity of client/server certificates. Allegedly, affected implementations will verify only the Certificate Authority, not the specific certificate owner. As a result, by impersonating a server or client and sending another host a specially formatted certificate with a trusted CA, an attacker may be capable of using this attack to carry out man-in-the-middle attacks against a session carried out between a legitimate client and server.
Although specific vendor product versions affected by this issue are not currently known, the researcher has stated that the following vendors are or may be affected: Microsoft Windows, Cisco, Nortel, FreeS\WAN and Certicom. It should be noted that other vendors/products may be affected as well.
Exploit / POC
Multiple Vendor IKE Implementation Certificate Authenticity Verification Vulnerability
It is reported that an exploit exists that leverages this issue. It is not known whether this exploit is circulating in the wild or not.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
It is reported that an exploit exists that leverages this issue. It is not known whether this exploit is circulating in the wild or not.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Multiple Vendor IKE Implementation Certificate Authenticity Verification Vulnerability
Solution:
Cisco has released a security notice, which outlines updates that are scheduled for release in the third quarter of 2004 to address this issue. This update will augment the Hybrid Auth model so that a group pre-shared key for VPN group identification is required. Please see the referenced notice for further details.
It has been reported that some vendors may have addressed this issue in their VPN clients and other software. This has not yet been confirmed by Symantec. Please contact the relevant vendor representative for further information regarding this issue.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Cisco has released a security notice, which outlines updates that are scheduled for release in the third quarter of 2004 to address this issue. This update will augment the Hybrid Auth model so that a group pre-shared key for VPN group identification is required. Please see the referenced notice for further details.
It has been reported that some vendors may have addressed this issue in their VPN clients and other software. This has not yet been confirmed by Symantec. Please contact the relevant vendor representative for further information regarding this issue.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Multiple Vendor IKE Implementation Certificate Authenticity Verification Vulnerability
References:
References: