Vulnerability Description
The Internet Key Exchange v1 main mode is vulnerable to offline dictionary or brute force attacks. Reusing a key pair across different versions and modes of IKE could lead to cross-protocol authentication bypasses. It is well known, that the aggressive mode of IKEv1 PSK is vulnerable to offline dictionary or brute force attacks. For the main mode, however, only an online attack against PSK authentication was thought to be feasible. This vulnerability could allow an attacker to recover a weak Pre-Shared Key or enable the impersonation of a victim host or network.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ietf | Internet Key Exchange | 1.0 |
Related Weaknesses (CWE)
References
- https://blogs.cisco.com/security/great-cipher-but-where-did-you-get-that-keyThird Party Advisory
- https://my.f5.com/manage/s/article/K42378447
- https://web-in-security.blogspot.com/2018/08/practical-dictionary-attack-on-ipseExploitThird Party Advisory
- https://www.kb.cert.org/vuls/id/857035Third Party AdvisoryUS Government Resource
- https://www.usenix.org/system/files/conference/usenixsecurity18/sec18-felsch.pdfThird Party Advisory
- https://blogs.cisco.com/security/great-cipher-but-where-did-you-get-that-keyThird Party Advisory
- https://my.f5.com/manage/s/article/K42378447
- https://web-in-security.blogspot.com/2018/08/practical-dictionary-attack-on-ipseExploitThird Party Advisory
- https://www.kb.cert.org/vuls/id/857035Third Party AdvisoryUS Government Resource
- https://www.usenix.org/system/files/conference/usenixsecurity18/sec18-felsch.pdfThird Party Advisory
FAQ
What is CVE-2018-5389?
CVE-2018-5389 is a vulnerability with a CVSS score of 5.9 (MEDIUM). The Internet Key Exchange v1 main mode is vulnerable to offline dictionary or brute force attacks. Reusing a key pair across different versions and modes of IKE could lead to cross-protocol authentica...
How severe is CVE-2018-5389?
CVE-2018-5389 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-5389?
Check the references section above for vendor advisories and patch information. Affected products include: Ietf Internet Key Exchange.