AES-XCBC-MAC Algorithm Vulnerability in IPsec

AES-XCBC-MAC Algorithm Vulnerability in IPsec

CVE-2005-2359 · MEDIUM Severity

AV:N/AC:L/AU:N/C:N/I:P/A:N

The AES-XCBC-MAC algorithm in IPsec in FreeBSD 5.3 and 5.4, when used for authentication without other encryption, uses a constant key instead of the one that was assigned by the system administrator, which can allow remote attackers to spoof packets to establish an IPsec session.

Learn more about our Web Application Penetration Testing UK.