cbcvebase.
CVE-2013-2944
published 2013-05-02

CVE-2013-2944: strongSwan 4.3.5 through 5.0.3, when using the OpenSSL plugin for ECDSA signature verification, allows remote attackers to authenticate as other users via an…

PriorityP425medium4.9CVSS 2.0
AVNACMAuSCPIPAN
EPSS
1.58%
72.8th percentile
strongSwan 4.3.5 through 5.0.3, when using the OpenSSL plugin for ECDSA signature verification, allows remote attackers to authenticate as other users via an invalid signature.

Affected

22 ranges
VendorProductVersion rangeFixed in
debianstrongswan< strongswan 4.6.4-7 (bookworm)strongswan 4.6.4-7 (bookworm)
strongswanstrongswan
strongswanstrongswan
strongswanstrongswan
strongswanstrongswan
strongswanstrongswan
strongswanstrongswan
strongswanstrongswan
strongswanstrongswan
strongswanstrongswan
strongswanstrongswan
strongswanstrongswan
strongswanstrongswan
strongswanstrongswan
strongswanstrongswan
strongswanstrongswan
strongswanstrongswan
strongswanstrongswan
strongswanstrongswan>= 0 < 4.6.4-74.6.4-7
strongswanstrongswan>= 0 < 4.6.4-74.6.4-7
strongswanstrongswan>= 0 < 4.6.4-74.6.4-7
strongswanstrongswan>= 0 < 4.6.4-74.6.4-7

CVSS provenance

nvdv2.04.9MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:N
osv4.9MEDIUM
vendor_debian4.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.