First published: Wed Dec 31 2003(Updated: )
SonicWALL firmware before 6.4.0.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted Internet Key Exchange (IKE) response packets, possibly including (1) a large Security Parameter Index (SPI) field, (2) a large number of payloads, or (3) a long payload.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SonicWALL SonicOS | <=6.4.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-1320 is classified as a high severity vulnerability due to its potential to allow denial of service and arbitrary code execution.
To fix CVE-2003-1320, upgrade the SonicWALL firmware to version 6.4.0.1 or later.
CVE-2003-1320 enables remote denial of service attacks and the possibility of executing arbitrary code.
SonicWALL firmware versions before 6.4.0.1 are affected by CVE-2003-1320.
Exploitation of CVE-2003-1320 can occur through crafted Internet Key Exchange (IKE) response packets with large or malformed fields.