Vulnerabilities > CVE-2004-2621 - Unspecified vulnerability in Nortel Contivity
Attack vector
NETWORK Attack complexity
HIGH Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
NONE Summary
Nortel Contivity VPN Client 2.1.7, 3.00, 3.01, 4.91, and 5.01, when opening a VPN tunnel, does not check the gateway certificate until after a dialog box has been displayed to the user, which creates a race condition that allows remote attackers to perform a man-in-the-middle (MITM) attack.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Hardware | 5 |
References
- http://secunia.com/advisories/12881
- http://securitytracker.com/id?1011846
- http://www.osvdb.org/11002
- http://www.securityfocus.com/bid/11495
- http://www130.nortelnetworks.com/cgi-bin/eserv/cs/main.jsp?level=6&category=8&subcategory=6&subtype=&DocumentOID=276620&RenditionID=REND159588
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17812