Vulnerability Name: | CVE-2002-0414 (CCN-8416) | ||||||||
Assigned: | 2002-03-04 | ||||||||
Published: | 2002-03-04 | ||||||||
Updated: | 2008-09-05 | ||||||||
Summary: | KAME-derived implementations of IPsec on NetBSD 1.5.2, FreeBSD 4.5, and other operating systems, does not properly consult the Security Policy Database (SPD), which could cause a Security Gateway (SG) that does not use Encapsulating Security Payload (ESP) to forward forged IPv4 packets. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Mon Mar 04 2002 - 10:30:18 CST BSD: IPv4 forwarding doesn't consult inbound SPD in KAME-derived IPsec Source: VULNWATCH Type: UNKNOWN 20020304 [VulnWatch] BSD: IPv4 forwarding doesn't consult inbound SPD in KAME-derived IPsec Source: MITRE Type: CNA CVE-2002-0414 Source: CCN Type: KAME Project Web site CVS log for kame/CHANGELOG Source: CONFIRM Type: UNKNOWN http://orange.kame.net/dev/cvsweb.cgi/kame/CHANGELOG Source: XF Type: Patch, Vendor Advisory kame-forged-packet-forwarding(8416) Source: OSVDB Type: UNKNOWN 5304 Source: CCN Type: OSVDB ID: 5304 KAME-derived IPsec Forged IPv4 Packet Forwarding Source: BUGTRAQ Type: Vendor Advisory 20020304 BSD: IPv4 forwarding doesn't consult inbound SPD in KAME-derived IPsec Source: BID Type: Patch, Vendor Advisory 4224 Source: CCN Type: BID-4224 Kame-Derived Stack Non-ESP IPV4 Forwarded Packets Policy Bypassing Vulnerability Source: XF Type: UNKNOWN kame-forged-packet-forwarding(8416) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |