HIGH · 7.5

CVE-2005-3768

Buffer overflow in the Internet Key Exchange version 1 (IKEv1) implementation in Symantec Dynamic VPN Services, as used in Enterprise Firewall, Gateway Security, and Firewall /VPN Appliance products, ...

Vulnerability Description

Buffer overflow in the Internet Key Exchange version 1 (IKEv1) implementation in Symantec Dynamic VPN Services, as used in Enterprise Firewall, Gateway Security, and Firewall /VPN Appliance products, allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
SymantecEnterprise Firewall8.0
SymantecFirewall Vpn Appliance 100All versions
SymantecFirewall Vpn Appliance 200All versions
SymantecGateway Security 3002.0
SymantecGateway Security 4002.0
SymantecGateway Security 5000 Series3.0
SymantecGateway Security 5100All versions
SymantecGateway Security 53001.0
SymantecGateway Security 53101.0
SymantecGateway Security 54002.0.1

References

FAQ

What is CVE-2005-3768?

CVE-2005-3768 is a vulnerability with a CVSS score of 7.5 (HIGH). Buffer overflow in the Internet Key Exchange version 1 (IKEv1) implementation in Symantec Dynamic VPN Services, as used in Enterprise Firewall, Gateway Security, and Firewall /VPN Appliance products, ...

How severe is CVE-2005-3768?

CVE-2005-3768 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2005-3768?

Check the references section above for vendor advisories and patch information. Affected products include: Symantec Enterprise Firewall, Symantec Firewall Vpn Appliance 100, Symantec Firewall Vpn Appliance 200, Symantec Gateway Security 300, Symantec Gateway Security 400.