CVE-2004-0369 describes a buffer overflow vulnerability within the Entrust LibKmp ISAKMP library. This flaw impacts several products, including Symantec Enterprise Firewall versions 7.0 through 8.0, Gateway Security 5300 1.0, Gateway Security 5400 2.0, and VelociRaptor 1.5. A remote attacker can exploit this vulnerability by sending a specially crafted ISAKMP payload, potentially leading to arbitrary code execution. The vulnerability carries a CVSS score of 7.5, indicating high severity. It can be exploited remotely with low attack complexity and no authentication required, allowing for potential compromise of confidentiality, integrity, and availability. The EPSS score of 0.08501 suggests a relatively low probability of exploitation in the wild compared to other CVEs. There is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. Furthermore, there is minimal community discussion or media coverage surrounding this CVE, suggesting it has not garnered significant attention from researchers or threat actors.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:entrust:entrust_libkmp_isakmp_library:*:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:a:symantec:enterprise_firewall:7.0:*:solaris:*:*:*:*:* | ||
7.0.4CPE matchmatch criteria | cpe:2.3:a:symantec:enterprise_firewall:7.0.4:*:solaris:*:*:*:*:* | ||
7.0.4CPE matchmatch criteria | cpe:2.3:a:symantec:enterprise_firewall:7.0.4:*:windows_2000_nt:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:a:symantec:enterprise_firewall:8.0:*:solaris:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.