Vulnerabilities
Vulnerable Software
Strongswan:  >> Strongswan  >> 4.3.2  Security Vulnerabilities
The GMP Plugin in strongSwan 4.2.0 through 4.6.3 allows remote attackers to bypass authentication via a (1) empty or (2) zeroed RSA signature, aka "RSA signature verification vulnerability."
CVSS Score
7.5
EPSS Score
0.033
Published
2012-06-27
The IKE daemon in strongSwan 4.3.x before 4.3.7 and 4.4.x before 4.4.1 does not properly check the return values of snprintf calls, which allows remote attackers to execute arbitrary code via crafted (1) certificate or (2) identity data that triggers buffer overflows.
CVSS Score
7.5
EPSS Score
0.041
Published
2010-08-20
The asn1_length function in strongSwan 2.8 before 2.8.11, 4.2 before 4.2.17, and 4.3 before 4.3.3 does not properly handle X.509 certificates with crafted Relative Distinguished Names (RDNs), which allows remote attackers to cause a denial of service (pluto IKE daemon crash) via malformed ASN.1 data. NOTE: this is due to an incomplete fix for CVE-2009-2185.
CVSS Score
5.0
EPSS Score
0.016
Published
2009-08-04


Contact Us

Shodan ® - All rights reserved