cbcvebase.
CVE-2014-2891
published 2014-05-07

CVE-2014-2891: strongSwan before 5.1.2 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon crash) via a crafted ID_DER_ASN1_DN ID…

PriorityP422medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.51%
83.0th percentile
strongSwan before 5.1.2 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon crash) via a crafted ID_DER_ASN1_DN ID payload.

Affected

13 ranges
VendorProductVersion rangeFixed in
debianstrongswan< strongswan 5.1.2-1 (bookworm)strongswan 5.1.2-1 (bookworm)
debianstrongswan<= 5.1.2
strongswanstrongswan<= 5.1.1
strongswanstrongswan
strongswanstrongswan
strongswanstrongswan
strongswanstrongswan
strongswanstrongswan
strongswanstrongswan
strongswanstrongswan>= 0 < 5.1.2-15.1.2-1
strongswanstrongswan>= 0 < 5.1.2-15.1.2-1
strongswanstrongswan>= 0 < 5.1.2-15.1.2-1
strongswanstrongswan>= 0 < 5.1.2-15.1.2-1

CVSS provenance

nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.