Nortel Networks Information for VU#459371

Multiple IPsec implementations do not adequately validate authentication data


Not Affected

Vendor Statement

The following Nortel Networks products implement IPsec but are not affected by the vulnerabilities noted in VU#459371:

The Preside Multi-Service Data Manager (MDM) is not affected.

There are no issues with the Contivity Platform, this includes the:

    Contivity 600/1500/1600/2000/2500/2600/4500/4600
    Contivity 1010/1050/1100
    Contivity 1700/2700
    Contivity software releases 3.5 and beyond including the Contivity VPN Client
The Shasta 5000 Broadband Services Node is not affected.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Vendor References



The CERT/CC has no additional comments at this time.

If you have feedback, comments, or additional information about this vulnerability, please send us email.