CVE-2003-1320

SonicWALL Firmware < 6.4.0.1 - Denial of Service and Possible Remote Code Execution via Crafted IKE Response Packets

Title source: llm
STIX 2.1

Description

SonicWALL firmware before 6.4.0.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted Internet Key Exchange (IKE) response packets, possibly including (1) a large Security Parameter Index (SPI) field, (2) a large number of payloads, or (3) a long payload.

References (2)

Core 2
Core References
Third Party Advisory, US Government Resource x_refsource_misc
http://www.kb.cert.org/vuls/id/AAMN-5L74VD
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/287771

Scores

EPSS 0.0123
EPSS Percentile 79.4%

Details

CWE
CWE-399
Status published
Products (1)
sonicwall/firmware < 6.4.0.1
Published Dec 31, 2003
Tracked Since Feb 18, 2026