Ipsec Tools is a narrowly scoped cryptographic utility suite for IPsec protocol implementation and key management, providing foundational components for VPN and encrypted network infrastructure despite minimal product diversification. The vendor occupies a prominent position in the vulnerability landscape relative to its size, reflecting the critical role these tools play in security-sensitive deployments and the complexity inherent in cryptographic software. Current severity, exploitation activity, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ipsec Tools over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-1574MEDIUM racoon/isakmp_frag.c in ipsec-tools before 0.7.2 allows remote attackers to cause a denial of service (crash) via crafted fragmented packets without a payload, which triggers a NUL | May 6, 2009 | 5.0 | 31 | NO | YES |
CVE-2004-0607HIGH The eay_check_x509cert function in KAME Racoon successfully verifies certificates even when OpenSSL validation fails, which could allow remote attackers to bypass authentication. | Dec 6, 2004 | 10.0 | 26 | NO | NO |
CVE-2016-10396HIGH The racoon daemon in IPsec-Tools 0.8.2 contains a remotely exploitable computational-complexity attack when parsing and storing ISAKMP fragments. The implementation permits a remot | Jul 6, 2017 | 7.5 | 25 | NO | NO |
CVE-2015-4047HIGH racoon/gssapi.c in IPsec-Tools 0.8.2 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon crash) via a series of crafted UDP requests. | May 29, 2015 | 7.8 | 23 | NO | NO |
CVE-2008-3652HIGH src/racoon/handler.c in racoon in ipsec-tools does not remove an "orphaned ph1" (phase 1) handle when it has been initiated remotely, which allows remote attackers to cause a denia | Aug 13, 2008 | 7.8 | 21 | NO | NO |
CVE-2005-3732HIGH The Internet Key Exchange version 1 (IKEv1) implementation (isakmp_agg.c) in racoon in ipsec-tools before 0.6.3, when running in aggressive mode, allows remote attackers to cause a | Nov 21, 2005 | 7.8 | 21 | NO | NO |
CVE-2009-1632MEDIUM Multiple memory leaks in Ipsec-tools before 0.7.2 allow remote attackers to cause a denial of service (memory consumption) via vectors involving (1) signature verification during u | May 14, 2009 | 5.0 | 16 | NO | NO |
CVE-2005-0398MEDIUM The KAME racoon daemon in ipsec-tools before 0.5 allows remote attackers to cause a denial of service (crash) via malformed ISAKMP packets. | Mar 14, 2005 | 5.0 | 15 | NO | NO |
CVE-2007-1841MEDIUM The isakmp_info_recv function in src/racoon/isakmp_inf.c in racoon in Ipsec-tools before 0.6.7 allows remote attackers to cause a denial of service (tunnel crash) via crafted (1) D | Apr 10, 2007 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ipsec Tools.
Media articles that mention a CVE ID that affects a product developed by Ipsec Tools — matched by CVE ID, not by vendor name.