CVE

Id
13565  
CVE No.
CVE-2005-2359  
Status
Candidate  
Description
The AES-XCBC-MAC algorithm in IPsec in FreeBSD 5.3 and 5.4, when used for authentication without other encryption, uses a constant key instead of the one that was assigned by the system administrator, which can allow remote attackers to spoof packets to establish an IPsec session.  
Phase
Assigned (20050726)  
Votes
None (candidate not yet proposed)  
Comments