Vulnerability Details CVE-2005-2359
The AES-XCBC-MAC algorithm in IPsec in FreeBSD 5.3 and 5.4, when used for authentication without other encryption, uses a constant key instead of the one that was assigned by the system administrator, which can allow remote attackers to spoof packets to establish an IPsec session.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 57.6%
CVSS Severity
CVSS v2 Score 5.0
Products affected by CVE-2005-2359
-
cpe:2.3:o:freebsd:freebsd:5.3
-
cpe:2.3:o:freebsd:freebsd:5.4