Vulnerability Details CVE-2023-38711
An issue was discovered in Libreswan before 4.12. When an IKEv1 Quick Mode connection configured with ID_IPV4_ADDR or ID_IPV6_ADDR receives an IDcr payload with ID_FQDN, a NULL pointer dereference causes a crash and restart of the pluto daemon. NOTE: the earliest affected version is 4.6.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 19.6%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2023-38711
-
cpe:2.3:a:libreswan:libreswan:4.10
-
cpe:2.3:a:libreswan:libreswan:4.11
-
cpe:2.3:a:libreswan:libreswan:4.6
-
cpe:2.3:a:libreswan:libreswan:4.7
-
cpe:2.3:a:libreswan:libreswan:4.8
-
cpe:2.3:a:libreswan:libreswan:4.9
-
cpe:2.3:a:libreswan:libreswan:4.9-1.el8
-
cpe:2.3:a:libreswan:libreswan:4.9-1.el9