CVE-2005-0039
Last modified
CVE-2005-0039 is a vulnerability of currently unknown severity. Certain configurations of IPsec, when using Encapsulating Security Payload (ESP) in tunnel mode, integrity protection at a higher layer, or Authentication Header (AH), allow remote attackers to decrypt IPSec communications by modifying the outer packet in ways that cause plaintext data from the inner packet to be returned in ICMP messages, as demonstrated using bit-flipping attacks and (1) Destination Address Rewriting, (2) a modified header length that causes portions of the packet to be interpreted as IP Options, or (3) a modified protocol field and source address.. EPSS estimates a 4.08% chance of exploitation in the next 30 days.
Description
Certain configurations of IPsec, when using Encapsulating Security Payload (ESP) in tunnel mode, integrity protection at a higher layer, or Authentication Header (AH), allow remote attackers to decrypt IPSec communications by modifying the outer packet in ways that cause plaintext data from the inner packet to be returned in ICMP messages, as demonstrated using bit-flipping attacks and (1) Destination Address Rewriting, (2) a modified header length that causes portions of the packet to be interpreted as IP Options, or (3) a modified protocol field and source address.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Nissc | Ipsec | 1.0 |
References
- http://www.kb.cert.org/vuls/id/302220US Government Resource
- http://www.kb.cert.org/vuls/id/302220US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-0039?
How severe is CVE-2005-0039?
How do I fix CVE-2005-0039?
Are you affected by CVE-2005-0039?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
