| CVE-ID |
CVE-2018-5389
|
• CVSS Severity Rating • Fix Information • Vulnerable Software Versions • SCAP Mappings • CPE Information
|
| Description |
| The Internet Key Exchange v1 main mode is vulnerable to offline
dictionary or brute force attacks. Reusing a key pair across different
versions and modes of IKE could lead to cross-protocol authentication
bypasses. It is well known, that the aggressive mode of IKEv1 PSK is
vulnerable to offline dictionary or brute force attacks. For the main
mode, however, only an online attack against PSK authentication was
thought to be feasible. This vulnerability could allow an attacker to
recover a weak Pre-Shared Key or enable the impersonation of a victim
host or network.
|
| References |
|
Note: References are provided for the convenience of the reader to help distinguish between vulnerabilities. The list is not intended to be complete.
|
|
|
| Assigning CNA |
| CERT/CC |
| Date Entry Created |
| 20180112 |
Disclaimer: The entry creation date may reflect when
the CVE ID was allocated or reserved, and does not
necessarily indicate when this vulnerability was
discovered, shared with the affected vendor, publicly
disclosed, or updated in CVE.
|
| Phase (Legacy) |
| Assigned (20180112) |
| Votes (Legacy) |
|
| Comments (Legacy) |
|
| Proposed (Legacy) |
| N/A |
|
This is an entry on the CVE List, which provides common identifiers for publicly known cybersecurity vulnerabilities. |
|
|
|
For More Information: cve@mitre.org
|