Beveiligingsadvies

CVE-2002-1623

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2005-03-26 05:00:00
Laatst bijgewerkt 2024-08-08 03:34:54
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

The design of the Internet Key Exchange (IKE) protocol, when using Aggressive Mode for shared secret authentication, does not encrypt initiator or responder identities during negotiation, which may allow remote attackers to determine valid usernames by (1) monitoring responses before the password is supplied or (2) sniffing, as originally reported for FireWall-1 SecuRemote.