Vulnerabilities
Vulnerable Software
Strongswan:  >> Strongswan  >> 4.3.6  Security Vulnerabilities
strongSwan 4.3.5 through 5.0.3, when using the OpenSSL plugin for ECDSA signature verification, allows remote attackers to authenticate as other users via an invalid signature.
CVSS Score
4.9
EPSS Score
0.016
Published
2013-05-02
The GMP Plugin in strongSwan 4.2.0 through 4.6.3 allows remote attackers to bypass authentication via a (1) empty or (2) zeroed RSA signature, aka "RSA signature verification vulnerability."
CVSS Score
7.5
EPSS Score
0.033
Published
2012-06-27
The IKE daemon in strongSwan 4.3.x before 4.3.7 and 4.4.x before 4.4.1 does not properly check the return values of snprintf calls, which allows remote attackers to execute arbitrary code via crafted (1) certificate or (2) identity data that triggers buffer overflows.
CVSS Score
7.5
EPSS Score
0.041
Published
2010-08-20


Contact Us

Shodan ® - All rights reserved