Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ccfp-7gpg-fg7v

Опубликовано: 30 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

The design of the Internet Key Exchange (IKE) protocol, when using Aggressive Mode for shared secret authentication, does not encrypt initiator or responder identities during negotiation, which may allow remote attackers to determine valid usernames by (1) monitoring responses before the password is supplied or (2) sniffing, as originally reported for FireWall-1 SecuRemote.

The design of the Internet Key Exchange (IKE) protocol, when using Aggressive Mode for shared secret authentication, does not encrypt initiator or responder identities during negotiation, which may allow remote attackers to determine valid usernames by (1) monitoring responses before the password is supplied or (2) sniffing, as originally reported for FireWall-1 SecuRemote.

EPSS

Процентиль: 99%
0.75045
Высокий

Связанные уязвимости

nvd
около 23 лет назад

The design of the Internet Key Exchange (IKE) protocol, when using Aggressive Mode for shared secret authentication, does not encrypt initiator or responder identities during negotiation, which may allow remote attackers to determine valid usernames by (1) monitoring responses before the password is supplied or (2) sniffing, as originally reported for FireWall-1 SecuRemote.

EPSS

Процентиль: 99%
0.75045
Высокий