CVE-2001-0376 describes a vulnerability in SonicWALL Tele2 and SOHO firewalls running 6.0.0.0 firmware, where IPSEC with IKE pre-shared keys are limited to 48 bytes instead of the intended 128 bytes. This significantly weakens the cryptographic strength, making pre-shared keys susceptible to brute-force attacks by remote attackers. Rated with a CVSS score of 7.5 (High), this vulnerability has a network attack vector, low attack complexity, and can lead to compromise of confidentiality, integrity, and availability. While there is no known active exploitation, public exploit code, or KEV listing, the vulnerability has garnered significant community discussion, indicating awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.0.0CPE matchmatch criteria | cpe:2.3:h:sonicwall:soho2:6.0.0:*:*:*:*:*:*:* | ||
6.0.0CPE matchmatch criteria | cpe:2.3:h:sonicwall:tele2:6.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.