Vulnerability Details CVE-2015-3966
The IPsec SA establishment process on Innominate mGuard devices with firmware 8.x before 8.1.7 allows remote authenticated users to cause a denial of service (VPN service restart) by leveraging a peer relationship to send a crafted configuration with compression.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 54.9%
CVSS Severity
CVSS v2 Score 4.0
Products affected by CVE-2015-3966
-
cpe:2.3:o:innominate:mguard_firmware:8.0.0
-
cpe:2.3:o:innominate:mguard_firmware:8.0.1
-
cpe:2.3:o:innominate:mguard_firmware:8.0.2
-
cpe:2.3:o:innominate:mguard_firmware:8.0.3
-
cpe:2.3:o:innominate:mguard_firmware:8.1.1
-
cpe:2.3:o:innominate:mguard_firmware:8.1.2
-
cpe:2.3:o:innominate:mguard_firmware:8.1.3
-
cpe:2.3:o:innominate:mguard_firmware:8.1.4
-
cpe:2.3:o:innominate:mguard_firmware:8.1.5
-
cpe:2.3:o:innominate:mguard_firmware:8.1.6