Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The design of the Internet Key Exchange (IKE) protocol, when using Aggressive Mode for shared secret authentication, does not encrypt initiator or responder identities during negotiation, which may allow remote attackers to determine valid usernames by (1) monitoring responses before the password is supplied or (2) sniffing, as originally reported for FireWall-1 SecuRemote.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Internet Key Exchange (IKE)协议设计漏洞
Vulnerability Description
Internet Key Exchange (IKE)协议设计在使用用于分享秘密认证的Aggressive模式时不能加密协商时的发起人或应答者身份。远程攻击者可以通过(1)在提供密码前监测响应或(2)嗅探判断有效用户名,该漏洞与防火墙-1 SecuRemote最初报告相同。
CVSS Information
N/A
Vulnerability Type
N/A