CVE-2007-6094: Input Validation
Published Nov 22, 2007
·Updated
The IPsec module in the VPN component in Ingate Firewall before 4.6.0 and SIParator before 4.6.0 allows remote attackers to cause a denial of service (module crash) via an IPsec Phase 2 proposal that lacks Perfect Forward Secrecy (PFS).
Affected Software
2 affected components
Ingate Ingate Firewall<=4.5.2
Ingate Ingate SIParator<=4.5.2
Event History
Nov 22, 2007
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-6094?
CVE-2007-6094 has a severity rating of moderate due to its potential to cause a denial of service.
2
How do I fix CVE-2007-6094?
To fix CVE-2007-6094, upgrade the Ingate Firewall or SIParator to version 4.6.0 or later.
3
What component is affected by CVE-2007-6094?
CVE-2007-6094 affects the IPsec module in the VPN component of Ingate Firewall and SIParator.
4
Can CVE-2007-6094 be exploited remotely?
Yes, CVE-2007-6094 can be exploited remotely by sending a malformed IPsec Phase 2 proposal.
5
What is the impact of CVE-2007-6094 exploitation?
Exploitation of CVE-2007-6094 can lead to a crash of the IPsec module, resulting in denial of service.