10

CVE-2004-0607

The eay_check_x509cert function in KAME Racoon successfully verifies certificates even when OpenSSL validation fails, which could allow remote attackers to bypass authentication.

Data is provided by the National Vulnerability Database (NVD)
Ipsec-toolsIpsec-tools Version0.3
Ipsec-toolsIpsec-tools Version0.3.1
Ipsec-toolsIpsec-tools Version0.3.2
Ipsec-toolsIpsec-tools Version0.3_rc1
Ipsec-toolsIpsec-tools Version0.3_rc2
Ipsec-toolsIpsec-tools Version0.3_rc3
Ipsec-toolsIpsec-tools Version0.3_rc4
Ipsec-toolsIpsec-tools Version0.3_rc5
KameRacoon
KameRacoon Version2003-07-11
KameRacoon Version2004-04-05
KameRacoon Version2004-04-07b
KameRacoon Version2004-05-03
RedhatEnterprise Linux Version3.0 Editionadvanced_servers
RedhatEnterprise Linux Version3.0 Editionenterprise_server
RedhatEnterprise Linux Version3.0 Editionworkstation
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 3.04% 0.861
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C