CVE-2016-10396 - CVE House
Back to Database
Status published High CVE-2016-10396

The racoon daemon in IPsec-Tools 0.8.2 contains a remotely exploitable...

Vulnerability Description

The racoon daemon in IPsec-Tools 0.8.2 contains a remotely exploitable computational-complexity attack when parsing and storing ISAKMP fragments. The implementation permits a remote attacker to exhaust computational resources on the remote endpoint by repeatedly sending ISAKMP fragment packets in a particular order such that the worst-case computational complexity is realized in the algorithm utilized to determine if reassembly of the fragments can take place.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2016-10396

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

ipsec-tools

View all reports →

Affected Software

ipsec-tools
Vulnerable Versions:
0.8.2

Timeline

Official Publish: July 6th, 2017
Last Modified: September 16th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.