← Vulnerability feed

Vulnerability record · CVE-2005-3671 · published 18 November 2005

CVE-2005-3671: Frees wan vulnerability

FFrees Wan · Frees Wan

The Internet Key Exchange version 1 (IKEv1) implementation in Openswan 2 (openswan-2) before 2.4.4, and freeswan in SUSE LINUX 9.1 before 2.04_1.5.4-1.23, allow remote attackers to cause a denial of service via (1) a crafted packet using 3DES with an invalid key length, or (2) unspecified inputs when Aggressive Mode is enabled and the PSK is known, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1.

7.8 CVSS 2.0 High EPSS 7.5% · top 5.7%
7.8CVSS 2.0 base score
7.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
34References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

The Internet Key Exchange version 1 (IKEv1) implementation in Openswan 2 (openswan-2) before 2.4.4, and freeswan in SUSE LINUX 9.1 before 2.04_1.5.4-1.23, allow remote attackers to cause a denial of service via (1) a crafted packet using 3DES with an invalid key length, or (2) unspecified inputs when Aggressive Mode is enabled and the PSK is known, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1.

AV:N/AC:L/Au:N/C:N/I:N/A:C

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://archives.neohapsis.com/archives/bugtraq/2005-12/0138.html
http://archives.neohapsis.com/archives/bugtraq/2005-12/0161.html
http://jvn.jp/niscc/NISCC-273756/index.html
http://secunia.com/advisories/17581
http://secunia.com/advisories/17680
http://secunia.com/advisories/17980
http://secunia.com/advisories/18115
http://securitytracker.com/id?1015214
http://www.ee.oulu.fi/research/ouspg/protos/testing/c09/isakmp/ Exploit
http://www.gentoo.org/security/en/glsa/glsa-200512-04.xml
http://www.kb.cert.org/vuls/id/226364 Third Party AdvisoryUS Government Resource
http://www.niscc.gov.uk/niscc/docs/re-20051114-01014.pdf?lang=en Vendor Advisory
http://www.novell.com/linux/security/advisories/2005_70_ipsec.html
http://www.openswan.org/niscc2/ PatchVendor Advisory
http://www.redhat.com/archives/fedora-announce-list/2005-November/msg00057.html
http://www.redhat.com/archives/fedora-announce-list/2005-November/msg00058.html
http://www.securityfocus.com/bid/15416 Patch
http://archives.neohapsis.com/archives/bugtraq/2005-12/0138.html
http://archives.neohapsis.com/archives/bugtraq/2005-12/0161.html
http://jvn.jp/niscc/NISCC-273756/index.html
http://secunia.com/advisories/17581
http://secunia.com/advisories/17680
http://secunia.com/advisories/17980
http://secunia.com/advisories/18115
http://securitytracker.com/id?1015214
http://www.ee.oulu.fi/research/ouspg/protos/testing/c09/isakmp/ Exploit
http://www.gentoo.org/security/en/glsa/glsa-200512-04.xml
http://www.kb.cert.org/vuls/id/226364 Third Party AdvisoryUS Government Resource
http://www.niscc.gov.uk/niscc/docs/re-20051114-01014.pdf?lang=en Vendor Advisory
http://www.novell.com/linux/security/advisories/2005_70_ipsec.html
http://www.openswan.org/niscc2/ PatchVendor Advisory
http://www.redhat.com/archives/fedora-announce-list/2005-November/msg00057.html
http://www.redhat.com/archives/fedora-announce-list/2005-November/msg00058.html
http://www.securityfocus.com/bid/15416 Patch

Track CVE-2005-3671 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2004-0590Frees wan vulnerabilityFreeS/WAN 1.x and 2.x, and other related products including superfreeswan 1.x, openswan 1.x before 1.0.6, openswan 2.x before 2.1.4, and strongSwan b…EPSS 2.8%7.5CVE-2018-15836Xelerance openswan improper verification of cryptographic signature vulnerabilityIn verify_signed_hash() in lib/liboswkeys/signatures.c in Openswan before 2.6.50.1, the RSA implementation does not verify the value of padding strin…EPSS 1.5%7.2CVE-2005-0162Openswan vulnerabilityStack-based buffer overflow in the get_internal_addresses function in the pluto application for Openswan 1.x before 1.0.9, and Openswan 2.x before 2.…EPSS 1.7%6.8CVE-2013-2053Xelerance openswan memory buffer overflow vulnerabilityBuffer overflow in the atodn function in Openswan before 2.6.39, when Opportunistic Encryption is enabled and an RSA key is being used, allows remote…EPSS 2.4%6.5CVE-2010-3753Xelerance openswan os command injection vulnerabilityprograms/pluto/xauth.c in the client in Openswan 2.6.26 through 2.6.28 allows remote authenticated gateways to execute arbitrary commands via shell m…EPSS 2.4%6.5CVE-2010-3302Xelerance openswan memory buffer overflow vulnerabilityBuffer overflow in programs/pluto/xauth.c in the client in Openswan 2.6.25 through 2.6.28 might allow remote authenticated gateways to execute arbitr…EPSS 3.9%6.5CVE-2010-3308Xelerance openswan code injection vulnerabilityBuffer overflow in programs/pluto/xauth.c in the client in Openswan 2.6.26 through 2.6.28 might allow remote authenticated gateways to execute arbitr…EPSS 4.0%6.5CVE-2010-3752Xelerance openswan os command injection vulnerabilityprograms/pluto/xauth.c in the client in Openswan 2.6.25 through 2.6.28 allows remote authenticated gateways to execute arbitrary commands via shell m…EPSS 2.5%

Source: NIST National Vulnerability Database (record CVE-2005-3671), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.