AES-XCBC-MAC Algorithm Vulnerability in IPsec
CVE-2005-2359 · MEDIUM Severity
AV:N/AC:L/AU:N/C:N/I:P/A:N
The AES-XCBC-MAC algorithm in IPsec in FreeBSD 5.3 and 5.4, when used for authentication without other encryption, uses a constant key instead of the one that was assigned by the system administrator, which can allow remote attackers to spoof packets to establish an IPsec session.
Learn more about our Web Application Penetration Testing UK.