AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2005-0039

MEDIUM · CVSS 6.4 EPSS 4.08%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2005-05-10 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 6.4. It may be remotely exploitable.

CVE
CVE-2005-0039
Severity
MEDIUM
CVSS
6.4
EPSS
4.08%

Original NVD Description

Certain configurations of IPsec, when using Encapsulating Security Payload (ESP) in tunnel mode, integrity protection at a higher layer, or Authentication Header (AH), allow remote attackers to decrypt IPSec communications by modifying the outer packet in ways that cause plaintext data from the inner packet to be returned in ICMP messages, as demonstrated using bit-flipping attacks and (1) Destination Address Rewriting, (2) a modified header length that causes portions of the packet to be interpreted as IP Options, or (3) a modified protocol field and source address.