CVE-2013-2944Improper Authentication in Strongswan

Severity
4.9MEDIUMNVD
EPSS
0.3%
top 45.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 2
Latest updateMay 14

Description

strongSwan 4.3.5 through 5.0.3, when using the OpenSSL plugin for ECDSA signature verification, allows remote attackers to authenticate as other users via an invalid signature.

CVSS vector

AV:N/AC:M/C:P/I:P/A:NExploitability: 6.8 | Impact: 4.9

Affected Packages3 packages

debiandebian/strongswan< strongswan 4.6.4-7 (bookworm)
Debianstrongswan/strongswan< 4.6.4-7+3
NVDstrongswan/strongswan17 versions+16

Patches

🔴Vulnerability Details

2
GHSA
GHSA-m484-f74p-8pvx: strongSwan 42022-05-14
OSV
CVE-2013-2944: strongSwan 42013-05-02

📋Vendor Advisories

1
Debian
CVE-2013-2944: strongswan - strongSwan 4.3.5 through 5.0.3, when using the OpenSSL plugin for ECDSA signatur...2013

💬Community

2
Bugzilla
CVE-2013-2944 strongswan: ECDSA signature flaw [fedora-all]2013-04-30
Bugzilla
CVE-2013-2944 strongswan: ECDSA signature flaw2013-04-30