Internet Key Exchange is a protocol framework fundamental to VPN and IPsec implementations across networking and security appliances, despite its narrow product scope. Observed disclosures reflect the protocol's core complexity and parsing demands; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Internet Key Exchange over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-3666HIGH Multiple unspecified format string vulnerabilities in multiple unspecified implementations of Internet Key Exchange version 1 (IKEv1) have multiple unspecified attack vectors and i | Nov 18, 2005 | 10.0 | 27 | NO | NO |
CVE-2005-3667MEDIUM Multiple unspecified vulnerabilities in multiple unspecified implementations of Internet Key Exchange version 1 (IKEv1) have multiple unspecified attack vectors and impacts related | Nov 18, 2005 | 5.0 | 17 | NO | NO |
CVE-2006-2298MEDIUM The Internet Key Exchange version 1 (IKEv1) implementation in the libike library in Solaris 9 and 10 allows remote attackers to cause a denial of service (in.iked daemon crash) via | May 10, 2006 | 5.0 | 16 | NO | NO |
CVE-2005-3668MEDIUM Multiple buffer overflows in multiple unspecified implementations of Internet Key Exchange version 1 (IKEv1) have multiple unspecified attack vectors and impacts related to denial | Nov 18, 2005 | 5.0 | 16 | NO | NO |
CVE-2006-1646MEDIUM The Internet Key Exchange version 1 (IKEv1) implementation (isakmp_agg.c) in the Shoichi Sakane KAME Project racoon, as used by NetBSD 1.6, 2.x before 20060119, certain FreeBSD rel | Apr 6, 2006 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Internet Key Exchange.
Media articles that mention a CVE ID that affects a product developed by Internet Key Exchange — matched by CVE ID, not by vendor name.