First published: Thu Dec 22 2005(Updated: )
The Internet Key Exchange version 1 (IKEv1) implementation in NEC UNIVERGE IX1000, IX2000, and IX3000 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details in the advisory, it is unclear which of CVE-2005-3666, CVE-2005-3667, and/or CVE-2005-3668 this issue applies to.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
NEC UNIVERGE | =ix1011 | |
NEC UNIVERGE | =ix2004 | |
NEC UNIVERGE | =ix1010 | |
NEC UNIVERGE | =ix2010 | |
NEC UNIVERGE | =ix2015 | |
NEC UNIVERGE | =ix2010 | |
NEC UNIVERGE | =ix1050 | |
NEC UNIVERGE | =ix2010 | |
NEC UNIVERGE | =ix3010 | |
NEC UNIVERGE | =ix1020 | |
NEC UNIVERGE | =ix2003 | |
NEC UNIVERGE | =ix2015 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-4465 is classified as a high severity vulnerability that can lead to denial of service and potential remote code execution.
To fix CVE-2005-4465, apply the latest firmware updates and patches released by NEC for the affected UNIVERGE IX1000 series devices.
CVE-2005-4465 affects several models including IX1010, IX1011, IX2003, IX2004, IX2010, IX2015, IX3000, and their variations.
Yes, CVE-2005-4465 may allow remote attackers to execute arbitrary code, potentially compromising sensitive data.
To mitigate the risks associated with CVE-2005-4465, ensure your devices are updated and implement network security measures such as firewalls to limit exposure.