VDB
CVE-2004-0164
CVE-2004-0164
PUBLISHED
CVSS 5 MEDIUM
KAME IKE daemon (racoon) does not properly handle hash values, which allows remote attackers to delete certificates via (1) a certain delete message that is not properly handled in isakmp.c or isakmp_inf.c, or (2) a certain INITIAL-CONTACT message that is not properly handled in isakmp_inf.c.
EPSS 6.66% · 93.7th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
6.66%
93.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| kame | racoon | all_versions |
| n/a | n/a | n/a |
Timeline
- CVE Published
- Sep 23, 2010 PoC Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Feb 10, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Jul 18, 2023 EPSS Score
References
- oval:org.mitre.oval:def:9737 vdb
- openbsd-isakmp-invalidspi-delete-sa(14117) vdb
- 20040114 Re: unauthorized deletion of IPsec (and ISAKMP) SAs in racoon mailing-list
- NetBSD-SA2004-001 vendor-advisory
- APPLE-SA-2004-02-23 vendor-advisory
- oval:org.mitre.oval:def:947 vdb
- 9416 vdb
- https://nvd.nist.gov/vuln/detail/CVE-2004-0164 advisory
- http://marc.info/?l=bugtraq&m=107403331309838&w=2 technical
- http://www.securityfocus.com/bid/9417 technical
- https://exchange.xforce.ibmcloud.com/vulnerabilities/14118 technical