Sygate Secure Enterprise (SSE) 3.5MR3 and earlier does not change the key used to encrypt data, which allows remote attackers to cause a denial of service (resource exhaustion) by capturing a session and repeatedly replaying the session.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/16945 | vdb entry |
http://marc.info/?l=bugtraq&m=109215685731675&w=2 | mailing list |
http://www.corsaire.com/advisories/c031120-002.txt | patch vendor advisory |