VulnerabilityModified
CVE-2004-0607
The eay_check_x509cert function in KAME Racoon successfully verifies certificates even when OpenSSL validation fails, which could allow remote attackers to bypass authentication.
HIGH 10.0EPSS 5.44%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.44%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The eay_check_x509cert function in KAME Racoon successfully verifies certificates even when OpenSSL validation fails, which could allow remote attackers to bypass authentication.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 5.44% probability · 92th percentile
- CISA KEV
- Not listed
- Affected
- ipsec-tools/ipsec-tools · kame/racoon · redhat/enterprise linux · redhat/enterprise linux desktop
- Source
- cve@mitre.org
References
- ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.10/SCOSA-2005.10.txt
- http://marc.info/?l=bugtraq&m=108726102304507&w=2
- http://marc.info/?l=bugtraq&m=108731967126033&w=2
- http://secunia.com/advisories/11863
- http://secunia.com/advisories/11877
- http://security.gentoo.org/glsa/glsa-200406-17.xmlPatch, Vendor Advisory
- http://securitytracker.com/id?1010495
- http://sourceforge.net/project/shownotes.php?release_id=245982
- http://www.osvdb.org/7113
- http://www.redhat.com/support/errata/RHSA-2004-308.html
- http://www.securityfocus.com/bid/10546Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16414
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9163
- ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.10/SCOSA-2005.10.txt
- http://marc.info/?l=bugtraq&m=108726102304507&w=2
- http://marc.info/?l=bugtraq&m=108731967126033&w=2
- http://secunia.com/advisories/11863
- http://secunia.com/advisories/11877
- http://security.gentoo.org/glsa/glsa-200406-17.xmlPatch, Vendor Advisory
- http://securitytracker.com/id?1010495
- http://sourceforge.net/project/shownotes.php?release_id=245982
- http://www.osvdb.org/7113
- http://www.redhat.com/support/errata/RHSA-2004-308.html
- http://www.securityfocus.com/bid/10546Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16414
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9163
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.