CVE-2004-0590

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
06/12/2004
Last modified:
03/04/2025

Description

FreeS/WAN 1.x and 2.x, and other related products including superfreeswan 1.x, openswan 1.x before 1.0.6, openswan 2.x before 2.1.4, and strongSwan before 2.1.3, allows remote attackers to authenticate using spoofed PKCS#7 certificates in which a self-signed certificate identifies an alternate Certificate Authority (CA) and spoofed issuer and subject.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:frees_wan:frees_wan:1:*:*:*:*:*:*:*
cpe:2.3:a:frees_wan:frees_wan:2:*:*:*:*:*:*:*
cpe:2.3:a:frees_wan:super_frees_wan:1:*:*:*:*:*:*:*
cpe:2.3:a:openswan:openswan:1:*:*:*:*:*:*:*
cpe:2.3:a:openswan:openswan:2:*:*:*:*:*:*:*
cpe:2.3:a:strongswan:strongswan:*:*:*:*:*:*:*:* 2.1.2 (including)