ipsec -- Incorrect key usage in AES-XCBC-MAC

Affected packages
5.4 <= FreeBSD < 5.4_6
5.* <= FreeBSD < 5.3_20


VuXML ID 2b6e47b1-0598-11da-86bc-000e0c2e438a
Discovery 2005-07-27
Entry 2005-08-05

Problem description

A programming error in the implementation of the AES-XCBC-MAC algorithm for authentication resulted in a constant key being used instead of the key specified by the system administrator.


If the AES-XCBC-MAC algorithm is used for authentication in the absence of any encryption, then an attacker may be able to forge packets which appear to originate from a different system and thereby succeed in establishing an IPsec session. If access to sensitive information or systems is controlled based on the identity of the source system, this may result in information disclosure or privilege escalation.


CVE Name CVE-2005-2359
FreeBSD Advisory SA-05:19.ipsec