积极预防 及时发现
快速响应 力保恢复
有6.0.0.0 fireware的SonicWALL Tele2和SOHO firewall使用I...
发布时间:2001-06-18 信息来源:管理员

CNCVE编号:CNCVE-20010376 CVE编号:CAN-2001-0376 安全级别:中 漏洞中文描述: 有6.0.0.0 fireware的SonicWALL Tele2和SOHO firewall使用IPSEC,其IKE预共享的口令没有考虑到完整的128字节的IKE预共享的口令的使用,IKE 预共享口令设计只支持48字节的口令。如果使用完全的128个字节的IKE预共享口令,这允许远程攻击者用更少的资源来对预共享口令进行强制攻击。 漏洞英文描述: SonicWALL Tele2 and SOHO firewalls with 6.0.0.0 firmware using IPSEC with IKE pre-shared keys do not allow for the use of full 128 byte IKE pre-shared keys, which is the intended design of the IKE pre-shared key, and only support 48 byte keys. This allow remote attackers use less resource to crack the password of brute force attack. 漏洞参考: BUGTRAQ:20010327 SonicWall IKE pre-shared key length bug and security concern URL:http://archives.neohapsis.com/archives/bugtraq/2001-03/0403.html XF:sonicwall-ike-shared-keys URL:http://xforce.iss.net/static/6304.php 系统类型: 其他 漏洞类型:配置错误