CVE-2014-2338
published 2014-04-16CVE-2014-2338: IKEv2 in strongSwan 4.0.7 before 5.1.3 allows remote attackers to bypass authentication by rekeying an IKE_SA during (1) initiation or (2) re-authentication…
PriorityP344medium6.4CVSS 2.0
AVNACLAuNCPIPAN
EPSS
2.38%
81.9th percentile
IKEv2 in strongSwan 4.0.7 before 5.1.3 allows remote attackers to bypass authentication by rekeying an IKE_SA during (1) initiation or (2) re-authentication, which triggers the IKE_SA state to be set to established.
Affected
62 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | strongswan | < strongswan 5.1.2-4 (bookworm) | strongswan 5.1.2-4 (bookworm) |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
| strongswan | strongswan | — | — |
CVSS provenance
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
osv6.4MEDIUM
vendor_debian6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-69p7-xxq6-hxwh: IKEv2 in strongSwan 4
ghsa_unreviewed·2022-05-17
CVE-2014-2338 [MEDIUM] CWE-287 GHSA-69p7-xxq6-hxwh: IKEv2 in strongSwan 4
IKEv2 in strongSwan 4.0.7 before 5.1.3 allows remote attackers to bypass authentication by rekeying an IKE_SA during (1) initiation or (2) re-authentication, which triggers the IKE_SA state to be set to established.
OSV
CVE-2014-2338: IKEv2 in strongSwan 4
osv·2014-04-16·CVSS 6.4
CVE-2014-2338 [MEDIUM] CVE-2014-2338: IKEv2 in strongSwan 4
IKEv2 in strongSwan 4.0.7 before 5.1.3 allows remote attackers to bypass authentication by rekeying an IKE_SA during (1) initiation or (2) re-authentication, which triggers the IKE_SA state to be set to established.
Debian
CVE-2014-2338: strongswan - IKEv2 in strongSwan 4.0.7 before 5.1.3 allows remote attackers to bypass authent...
vendor_debian·2014·CVSS 6.4
CVE-2014-2338 [MEDIUM] CVE-2014-2338: strongswan - IKEv2 in strongSwan 4.0.7 before 5.1.3 allows remote attackers to bypass authent...
IKEv2 in strongSwan 4.0.7 before 5.1.3 allows remote attackers to bypass authentication by rekeying an IKE_SA during (1) initiation or (2) re-authentication, which triggers the IKE_SA state to be set to established.
Scope: local
bookworm: resolved (fixed in 5.1.2-4)
bullseye: resolved (fixed in 5.1.2-4)
forky: resolved (fixed in 5.1.2-4)
sid: resolved (fixed in 5.1.2-4)
trixie: resolved (fixed in 5.1.2-4)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-2338 strongswan: authentication bypass flaw in IKEv2 [epel-6]
bugzilla·2014-04-15·CVSS 6.4
CVE-2014-2338 [MEDIUM] CVE-2014-2338 strongswan: authentication bypass flaw in IKEv2 [epel-6]
CVE-2014-2338 strongswan: authentication bypass flaw in IKEv2 [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-6 tracking bug for stron
Bugzilla
CVE-2014-2338 strongswan: authentication bypass flaw in IKEv2 [fedora-all]
bugzilla·2014-04-15·CVSS 6.4
CVE-2014-2338 [MEDIUM] CVE-2014-2338 strongswan: authentication bypass flaw in IKEv2 [fedora-all]
CVE-2014-2338 strongswan: authentication bypass flaw in IKEv2 [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affect
Bugzilla
CVE-2014-2338 strongswan: authentication bypass flaw in IKEv2
bugzilla·2014-03-27·CVSS 6.4
CVE-2014-2338 [MEDIUM] CVE-2014-2338 strongswan: authentication bypass flaw in IKEv2
CVE-2014-2338 strongswan: authentication bypass flaw in IKEv2
An authentication bypass vulnerability was found in the strongSwan IKEv2 code. This flaw can be triggered by rekeying an unestablished IKE_SA while it is being actively initiated. This would allow an attacker to trick a peer's IKE_SA state to established, without having to provide any valid authentication credentials. While this flaw allows for the bypass of authentication, it does not allow for remote code execution.
Only installations that actively initiate or re-authenticate IKEv2 IKE_SAs are afected; IKEv1 in charon or pluto is not affected.
Acknowledgements:
Red Hat would like to thank the strongSwan project for reporting this issue.
Discussion:
Created attachment 879664
upstream patch for 5.x
---
libreswan and ope
http://lists.opensuse.org/opensuse-security-announce/2014-04/msg00010.htmlhttp://lists.opensuse.org/opensuse-updates/2014-05/msg00064.htmlhttp://lists.opensuse.org/opensuse-updates/2014-05/msg00066.htmlhttp://secunia.com/advisories/57823http://www.debian.org/security/2014/dsa-2903http://www.securityfocus.com/bid/66815http://www.strongswan.org/blog/2014/04/14/strongswan-authentication-bypass-vulnerability-%28cve-2014-2338%29.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-04/msg00010.htmlhttp://lists.opensuse.org/opensuse-updates/2014-05/msg00064.htmlhttp://lists.opensuse.org/opensuse-updates/2014-05/msg00066.htmlhttp://secunia.com/advisories/57823http://www.debian.org/security/2014/dsa-2903http://www.securityfocus.com/bid/66815http://www.strongswan.org/blog/2014/04/14/strongswan-authentication-bypass-vulnerability-%28cve-2014-2338%29.html
2014-04-16
Published