CVE-2008-1198
Last modified
CVE-2008-1198 is a vulnerability of currently unknown severity. The default IPSec ifup script in Red Hat Enterprise Linux 3 through 5 configures racoon to use aggressive IKE mode instead of main IKE mode, which makes it easier for remote attackers to conduct brute force attacks by sniffing an unencrypted preshared key (PSK) hash.. EPSS estimates a 2.43% chance of exploitation in the next 30 days.
Description
The default IPSec ifup script in Red Hat Enterprise Linux 3 through 5 configures racoon to use aggressive IKE mode instead of main IKE mode, which makes it easier for remote attackers to conduct brute force attacks by sniffing an unencrypted preshared key (PSK) hash.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Enterprise Linux | 4.0 |
| Redhat | Enterprise Linux | 3.0 |
| Redhat | Enterprise Linux | 5.0 |
References
- http://secunia.com/advisories/48045Broken Link
- http://www.securitytracker.com/id?1019563Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=435274Issue Tracking
- http://secunia.com/advisories/48045Broken Link
- http://www.securitytracker.com/id?1019563Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=435274Issue Tracking
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-1198?
How severe is CVE-2008-1198?
How do I fix CVE-2008-1198?
Are you affected by CVE-2008-1198?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
