5
CVSSv2

CVE-2013-7294

Published: 16/01/2014 Updated: 03/01/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The ikev2parent_inI1outR1 function in pluto/ikev2_parent.c in libreswan prior to 3.7 allows remote malicious users to cause a denial of service (restart) via an IKEv2 I1 notification without a KE payload.

Vulnerable Product Search on Vulmon Subscribe to Product

libreswan libreswan 3.0

libreswan libreswan 3.1

libreswan libreswan 3.2

libreswan libreswan 3.3

libreswan libreswan 3.4

libreswan libreswan 3.5

libreswan libreswan

Vendor Advisories

The ikev2parent_inI1outR1 function in pluto/ikev2_parentc in libreswan before 37 allows remote attackers to cause a denial of service (restart) via an IKEv2 I1 notification without a KE payload ...