Short Name |
IKE:SA-DELETE |
---|---|
Severity |
High |
Recommended |
No |
Recommended Action |
Drop |
Category |
IKE |
Keywords |
Malicious IKE Packets Delete IPsec SA or all SAs |
Release Date |
2015/06/15 |
Update Number |
2506 |
Supported Platforms |
idp-5.0.110121210+, isg-3.4.139899+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects attempts to exploit a known vulnerability against IKE Daemon. A successful exploit can remove an IPsec SA or all SAs.
It has been reported that it may be possible for attackers to remotely delete security associations (SAs) in hosts running the KAME IKE daemon Racoon.