CVE-2004-0221
Status: ModifiedMedium (5)—
isakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with a delete payload containing a large number of SPIs, which triggers an out-of-bounds read error, as demonstrated by the Striker ISAKMP Protocol Test Suite.
CVSS
- Version: 2.0
- Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P
- Base score: 5
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 3.62%
- Percentile among all scored CVEs: 89
- Score date: 10/7/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-125
References
- http://marc.info/?l=bugtraq&m=108008530028019&w=2
- http://www.kb.cert.org/vuls/id/524497
- http://www.openbsd.org/errata.html
- http://www.rapid7.com/advisories/R7-0018.html
- http://www.securityfocus.com/bid/9907
- http://www.securitytracker.com/alerts/2004/Mar/1009468.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15630
- http://marc.info/?l=bugtraq&m=108008530028019&w=2
- http://www.kb.cert.org/vuls/id/524497
- http://www.openbsd.org/errata.html
- http://www.rapid7.com/advisories/R7-0018.html
- http://www.securityfocus.com/bid/9907
- http://www.securitytracker.com/alerts/2004/Mar/1009468.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15630
Raw JSON (NVD)
Show
{
"id": "CVE-2004-0221",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2004-05-04T04:00:00.000",
"references": [
{
"url": "http://marc.info/?l=bugtraq&m=108008530028019&w=2",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.kb.cert.org/vuls/id/524497",
"tags": [
"Third Party Advisory",
"US Government Resource"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.openbsd.org/errata.html",
"tags": [
"Product",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.rapid7.com/advisories/R7-0018.html",
"tags": [
"Broken Link"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/9907",
"tags": [
"Broken Link",
"Third Party Advisory",
"VDB Entry"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securitytracker.com/alerts/2004/Mar/1009468.html",
"tags": [
"Broken Link",
"Third Party Advisory",
"VDB Entry"
],
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/15630",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "cve@mitre.org"
},
{
"url": "http://marc.info/?l=bugtraq&m=108008530028019&w=2",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.kb.cert.org/vuls/id/524497",
"tags": [
"Third Party Advisory",
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.openbsd.org/errata.html",
"tags": [
"Product",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.rapid7.com/advisories/R7-0018.html",
"tags": [
"Broken Link"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/9907",
"tags": [
"Broken Link",
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/alerts/2004/Mar/1009468.html",
"tags": [
"Broken Link",
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/15630",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-125"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "isakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with a delete payload containing a large number of SPIs, which triggers an out-of-bounds read error, as demonstrated by the Striker ISAKMP Protocol Test Suite."
},
{
"lang": "es",
"value": "isakmpd en OpenBSD 3.4 y anteriores permite a atacantes remotos causar una denegación de servicio (caída) mediante un paquete ISAKMP con una carga útil de borrado conteniendo un gran número de SPIs, lo que dispara un error de lectura fuera de límites, como se ha demostrado por el paquete de pruebas de protocolo ISAKMP Striker."
}
],
"lastModified": "2026-06-16T22:05:11.990",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:openbsd:openbsd:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C5DFD8FE-5B7A-4A71-B9C8-BF7E9F0F7DB9",
"versionEndIncluding": "3.4"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}