CVE-2005-3669

UnknownEPSS 5.14%

Last modified

CVE-2005-3669 is a vulnerability of currently unknown severity. Multiple unspecified vulnerabilities in the Internet Key Exchange version 1 (IKEv1) implementation in multiple Cisco products allow remote attackers to cause a denial of service (device reset) via certain malformed IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details in the Cisco advisory, it is unclear which of CVE-2005-3666, CVE-2005-3667, and/or CVE-2005-3668 this issue applies to.. EPSS estimates a 5.14% chance of exploitation in the next 30 days.

Description

Multiple unspecified vulnerabilities in the Internet Key Exchange version 1 (IKEv1) implementation in multiple Cisco products allow remote attackers to cause a denial of service (device reset) via certain malformed IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details in the Cisco advisory, it is unclear which of CVE-2005-3666, CVE-2005-3667, and/or CVE-2005-3668 this issue applies to.

Metrics

EPSS Probability
5.14%

91.3th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
CiscoFirewall Services ModuleAll versions
CiscoFirewall Services Module1.1.2
CiscoFirewall Services Module1.1.3
CiscoFirewall Services Module1.1_\(3.005\)
CiscoFirewall Services Module2.1_\(0.208\)
CiscoVpn 3000 Concentrator Series Software2.0
CiscoVpn 3000 Concentrator Series Software2.5.2.a
CiscoVpn 3000 Concentrator Series Software2.5.2.b
CiscoVpn 3000 Concentrator Series Software2.5.2.c
CiscoVpn 3000 Concentrator Series Software2.5.2.d
CiscoVpn 3000 Concentrator Series Software2.5.2.f
CiscoVpn 3000 Concentrator Series Software3.0
CiscoVpn 3000 Concentrator Series Software3.0.3.a
CiscoVpn 3000 Concentrator Series Software3.0.3.b
CiscoVpn 3000 Concentrator Series Software3.0.4
CiscoVpn 3000 Concentrator Series Software3.1
CiscoVpn 3000 Concentrator Series Software3.1\(rel\)
CiscoVpn 3000 Concentrator Series Software3.1.1
CiscoVpn 3000 Concentrator Series Software3.1.2
CiscoVpn 3000 Concentrator Series Software3.1.4
CiscoVpn 3000 Concentrator Series Software3.5\(rel\)
CiscoVpn 3000 Concentrator Series Software3.5.1
CiscoVpn 3000 Concentrator Series Software3.5.2
CiscoVpn 3000 Concentrator Series Software3.5.3
CiscoVpn 3000 Concentrator Series Software3.5.4
CiscoVpn 3000 Concentrator Series Software3.5.5
CiscoVpn 3000 Concentrator Series Software3.6
CiscoVpn 3000 Concentrator Series Software3.6.1
CiscoVpn 3000 Concentrator Series Software3.6.7
CiscoVpn 3000 Concentrator Series Software3.6.7d
CiscoVpn 3000 Concentrator Series Software4.0
CiscoVpn 3000 Concentrator Series Software4.0.1
CiscoVpn 3000 Concentrator Series Software4.0.5.b
CiscoVpn 3000 Concentrator Series Software4.1.5.b
CiscoVpn 3000 Concentrator Series Software4.1.7.a
CiscoVpn 3000 Concentrator Series Software4.1.7.b
CiscoVpn 3000 Concentrator Series Software4.7.1
CiscoVpn 3000 Concentrator Series Software4.7.1.f
CiscoIos12.2sxd
CiscoIos12.3t
CiscoIos12.3tpc
CiscoIos12.3xd
CiscoIos12.3xe
CiscoIos12.3xf
CiscoIos12.3xg
CiscoIos12.3xh
CiscoIos12.3xi
CiscoIos12.3xj
CiscoIos12.3xk
CiscoIos12.3xm

Showing 50 of 138 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2005-3669?
Multiple unspecified vulnerabilities in the Internet Key Exchange version 1 (IKEv1) implementation in multiple Cisco products allow remote attackers to cause a denial of service (device reset) via certain malformed IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details in the Cisco advisory, it is unclear which of CVE-2005-3666, CVE-2005-3667, and/or CVE-2005-3668 this issue applies to.
How severe is CVE-2005-3669?
Severity scoring for CVE-2005-3669 is pending analysis. The EPSS model estimates a 5.14% probability of exploitation in the next 30 days.
How do I fix CVE-2005-3669?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2005-3669?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST