Vulnerabilities > CVE-2004-2621 - Unspecified vulnerability in Nortel Contivity
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Nortel Contivity VPN Client 2.1.7, 3.00, 3.01, 4.91, and 5.01, when opening a VPN tunnel, does not check the gateway certificate until after a dialog box has been displayed to the user, which creates a race condition that allows remote attackers to perform a man-in-the-middle (MITM) attack.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Hardware | 5 |
References
- http://www.securityfocus.com/bid/11495
- http://www.osvdb.org/11002
- http://securitytracker.com/id?1011846
- http://secunia.com/advisories/12881
- http://www130.nortelnetworks.com/cgi-bin/eserv/cs/main.jsp?level=6&category=8&subcategory=6&subtype=&DocumentOID=276620&RenditionID=REND159588
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17812