CVE-2015-3240

Severity CVSS v4.0:
Pending analysis
Type:
CWE-189 Numeric Errors
Publication date:
09/11/2015
Last modified:
12/04/2025

Description

The pluto IKE daemon in libreswan before 3.15 and Openswan before 2.6.45, when built with NSS, allows remote attackers to cause a denial of service (assertion failure and daemon restart) via a zero DH g^x value in a KE payload in a IKE packet.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:libreswan:libreswan:3.14:*:*:*:*:*:*:*