Security Advisory

CVE-2004-0155

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2004-04-16 04:00:00
Last updated 2024-08-08 00:10:03
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

The KAME IKE Daemon Racoon, when authenticating a peer during Phase 1, validates the X.509 certificate but does not verify the RSA signature authentication, which allows remote attackers to establish unauthorized IP connections or conduct man-in-the-middle attacks using a valid, trusted X.509 certificate.