CVE-2004-0369

critical

Description

Buffer overflow in Entrust LibKmp ISAKMP library, as used by Symantec Enterprise Firewall 7.0 through 8.0, Gateway Security 5300 1.0, Gateway Security 5400 2.0, and VelociRaptor 1.5, allows remote attackers to execute arbitrary code via a crafted ISAKMP payload.

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/15669

http://xforce.iss.net/xforce/alerts/id/181

http://www.securityfocus.com/bid/11039

http://www.ciac.org/ciac/bulletins/o-206.shtml

http://www.auscert.org.au/render.html?it=4339

http://securityresponse.symantec.com/avcenter/security/Content/2004.08.26.html

Details

Source: Mitre, NVD

Published: 2004-12-31

Updated: 2026-06-16

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Severity: High

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.08501