CVE-2019-10155

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
12/06/2019
Last modified:
07/11/2023

Description

The Libreswan Project has found a vulnerability in the processing of IKEv1 informational exchange packets which are encrypted and integrity protected using the established IKE SA encryption and integrity keys, but as a receiver, the integrity check value was not verified. This issue affects versions before 3.29.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:libreswan:libreswan:*:*:*:*:*:*:*:* 3.29 (excluding)
cpe:2.3:a:strongswan:strongswan:*:*:*:*:*:*:*:* 5.0.0 (excluding)
cpe:2.3:a:xelerance:openswan:*:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*