ISAKMPD "Initial Contact"...

- AV AC AU C I A
发布: 2004-01-01
修订: 2025-04-13

It has been reported that it is possible for attackers to remotely delete SAs (security associations) in hosts running isakmpd. When isakmpd receives an "INITIAL CONTACT" notification that is attached to a payload considered "reasonable", it will delete the SA associated with the IP address from which the message originated. All associated SAs will be deleted as well. Notifications of "INITIAL CONTACT" will be ignored if the messages to which they are chained are part of an informational exchange.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息