vendor:
racoon
by:
mu-b
7.5
CVSS
HIGH
Denial of Service (DoS)
400
CWE
Product Name: racoon
Affected Version From: ipsec-tools-0.7.1
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE: a:ipsec-tools:racoon
Platforms Tested: Unknown
2009
ipsec-tools racoon frag-isakmp DoS POC
This is a proof of concept (POC) exploit for a Denial of Service (DoS) vulnerability in the ipsec-tools racoon service. The vulnerability allows an attacker to send a specially crafted packet to the service, causing it to crash or become unresponsive. The exploit takes advantage of a flaw in the handling of IKE fragmentation payloads, which can be used to exhaust system resources and disrupt the normal operation of the service. This POC has been tested on ipsec-tools-0.7.1.
Mitigation:
To mitigate this vulnerability, it is recommended to update to a patched version of the ipsec-tools racoon service or apply any available security patches. Additionally, it is advised to implement network-level protections, such as firewalls or intrusion detection systems, to detect and block malicious traffic targeting the service.