CVE-2023-30570

Severity CVSS v4.0:
Pending analysis
Type:
CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
29/05/2023
Last modified:
14/01/2025

Description

pluto in Libreswan before 4.11 allows a denial of service (responder SPI mishandling and daemon crash) via unauthenticated IKEv1 Aggressive Mode packets. The earliest affected version is 3.28.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:libreswan:libreswan:*:*:*:*:*:*:*:* 3.28 (including) 4.10 (including)