4
CVSSv2

CVE-2004-2621

Published: 31/12/2004 Updated: 20/07/2017
CVSS v2 Base Score: 4 | Impact Score: 4.9 | Exploitability Score: 4.9
VMScore: 356
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:N

Vulnerability Summary

Nortel Contivity VPN Client 2.1.7, 3.00, 3.01, 4.91, and 5.01, when opening a VPN tunnel, does not check the gateway certificate until after a dialog box has been displayed to the user, which creates a race condition that allows remote malicious users to perform a man-in-the-middle (MITM) attack.

Vulnerable Product Search on Vulmon Subscribe to Product

nortel contivity 4.91

nortel contivity 5.01

nortel contivity 3.00

nortel contivity 3.01

nortel contivity 2.1.7