CVE-2012-2388
published 2012-06-27CVE-2012-2388: The GMP Plugin in strongSwan 4.2.0 through 4.6.3 allows remote attackers to bypass authentication via a (1) empty or (2) zeroed RSA signature, aka "RSA…
PriorityP348high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
3.32%
87.2th percentile
The GMP Plugin in strongSwan 4.2.0 through 4.6.3 allows remote attackers to bypass authentication via a (1) empty or (2) zeroed RSA signature, aka "RSA signature verification vulnerability."
Affected
39 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | strongswan | < strongswan 4.5.2-1.4 (bookworm) | strongswan 4.5.2-1.4 (bookworm) |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4cvm-fc9f-m7w8: The GMP Plugin in strongSwan 4
ghsa_unreviewed·2022-05-17
CVE-2012-2388 [HIGH] CWE-287 GHSA-4cvm-fc9f-m7w8: The GMP Plugin in strongSwan 4
The GMP Plugin in strongSwan 4.2.0 through 4.6.3 allows remote attackers to bypass authentication via a (1) empty or (2) zeroed RSA signature, aka "RSA signature verification vulnerability."
OSV
CVE-2012-2388: The GMP Plugin in strongSwan 4
osv·2012-06-27·CVSS 7.5
CVE-2012-2388 [HIGH] CVE-2012-2388: The GMP Plugin in strongSwan 4
The GMP Plugin in strongSwan 4.2.0 through 4.6.3 allows remote attackers to bypass authentication via a (1) empty or (2) zeroed RSA signature, aka "RSA signature verification vulnerability."
Debian
CVE-2012-2388: strongswan - The GMP Plugin in strongSwan 4.2.0 through 4.6.3 allows remote attackers to bypa...
vendor_debian·2012·CVSS 7.5
CVE-2012-2388 [HIGH] CVE-2012-2388: strongswan - The GMP Plugin in strongSwan 4.2.0 through 4.6.3 allows remote attackers to bypa...
The GMP Plugin in strongSwan 4.2.0 through 4.6.3 allows remote attackers to bypass authentication via a (1) empty or (2) zeroed RSA signature, aka "RSA signature verification vulnerability."
Scope: local
bookworm: resolved (fixed in 4.5.2-1.4)
bullseye: resolved (fixed in 4.5.2-1.4)
forky: resolved (fixed in 4.5.2-1.4)
sid: resolved (fixed in 4.5.2-1.4)
trixie: resolved (fixed in 4.5.2-1.4)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-2388 strongswan: authentication bypass due to RSA signature verification flaw [fedora-all]
bugzilla·2012-06-04·CVSS 7.5
CVE-2012-2388 [HIGH] CVE-2012-2388 strongswan: authentication bypass due to RSA signature verification flaw [fedora-all]
CVE-2012-2388 strongswan: authentication bypass due to RSA signature verification flaw [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/upd
Bugzilla
CVE-2012-2388 strongswan: authentication bypass due to RSA signature verification flaw [epel-6]
bugzilla·2012-06-04·CVSS 7.5
CVE-2012-2388 [HIGH] CVE-2012-2388 strongswan: authentication bypass due to RSA signature verification flaw [epel-6]
CVE-2012-2388 strongswan: authentication bypass due to RSA signature verification flaw [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates
Bugzilla
CVE-2012-2388 strongswan: authentication bypass due to RSA signature verification flaw
bugzilla·2012-06-04·CVSS 7.5
CVE-2012-2388 [HIGH] CVE-2012-2388 strongswan: authentication bypass due to RSA signature verification flaw
CVE-2012-2388 strongswan: authentication bypass due to RSA signature verification flaw
strongSwan 4.6.4 was released [1] to fix a security flaw in 4.2.0 through to 4.6.3. If the gmp plugin were used for RSA signature verification with IKEv1 or IKEv2, an empty or zeroed signature was handled as a legitimate one. A connection definition using RSA authentication is required to exploit this flaw, and an attacker presenting a forged signature and/or certificate could authenticate as any legitimate user.
The fix is present in version 4.6.4 or as a patch [2].
[1] http://www.strongswan.org/blog/2012/05/31/strongswan-4.6.4-released-(cve-2012-2388).html
[2] http://download.strongswan.org/patches/09_gmp_rsa_signature_patch/strongswan-4.2.0-4.6.3_gmp_rsa_signature.patch
Discussion:
Created strong
http://lists.opensuse.org/opensuse-security-announce/2012-06/msg00002.htmlhttp://osvdb.org/82587http://secunia.com/advisories/49315http://secunia.com/advisories/49336http://secunia.com/advisories/49370http://secunia.com/advisories/55051http://www.debian.org/security/2012/dsa-2483http://www.securityfocus.com/bid/53752http://www.securitytracker.com/id?1027110http://www.strongswan.org/blog/2012/05/31/strongswan-4.6.4-released-%28cve-2012-2388%29.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/76013http://lists.opensuse.org/opensuse-security-announce/2012-06/msg00002.htmlhttp://osvdb.org/82587http://secunia.com/advisories/49315http://secunia.com/advisories/49336http://secunia.com/advisories/49370http://secunia.com/advisories/55051http://www.debian.org/security/2012/dsa-2483http://www.securityfocus.com/bid/53752http://www.securitytracker.com/id?1027110http://www.strongswan.org/blog/2012/05/31/strongswan-4.6.4-released-%28cve-2012-2388%29.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/76013
2012-06-27
Published