CVE-2023-2295
published 2023-05-17CVE-2023-2295: A vulnerability was found in the libreswan library. This security issue occurs when an IKEv1 Aggressive Mode packet is received with only unacceptable crypto…
PriorityP345high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.58%
73.0th percentile
A vulnerability was found in the libreswan library. This security issue occurs when an IKEv1 Aggressive Mode packet is received with only unacceptable crypto algorithms, and the response packet is not sent with a zero responder SPI. When a subsequent packet is received where the sender reuses the libreswan responder SPI as its own initiator SPI, the pluto daemon state machine crashes. No remote code execution is possible. This CVE exists because of a CVE-2023-30570 security regression for libreswan package in Red Hat Enterprise Linux 8.8 and Red Hat Enterprise Linux 9.2.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| libreswan | libreswan | — | — |
| libreswan | libreswan | — | — |
| libreswan | libreswan | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gcrh-c42h-m2vw: A vulnerability was found in the libreswan library
ghsa_unreviewed·2023-05-18·CVSS 7.5
CVE-2023-2295 [HIGH] CWE-400 GHSA-gcrh-c42h-m2vw: A vulnerability was found in the libreswan library
A vulnerability was found in the libreswan library. This security issue occurs when an IKEv1 Aggressive Mode packet is received with only unacceptable crypto algorithms, and the response packet is not sent with a zero responder SPI. When a subsequent packet is received where the sender reuses the libreswan responder SPI as its own initiator SPI, the pluto daemon state machine crashes. No remote code execution is possible. This CVE exists because of a CVE-2023-30570 security regression for libreswan package in Red Hat Enterprise Linux 8.8 and Red Hat Enterprise Linux 9.2.
OSV
CVE-2023-2295: A vulnerability was found in the libreswan library
osv·2023-05-17·CVSS 7.5
CVE-2023-2295 [HIGH] CVE-2023-2295: A vulnerability was found in the libreswan library
A vulnerability was found in the libreswan library. This security issue occurs when an IKEv1 Aggressive Mode packet is received with only unacceptable crypto algorithms, and the response packet is not sent with a zero responder SPI. When a subsequent packet is received where the sender reuses the libreswan responder SPI as its own initiator SPI, the pluto daemon state machine crashes. No remote code execution is possible. This CVE exists because of a CVE-2023-30570 security regression for libreswan package in Red Hat Enterprise Linux 8.8 and Red Hat Enterprise Linux 9.2.
Red Hat
libreswan: Regression of CVE-2023-30570 fixes in the Red Hat Enterprise Linux
vendor_redhat·2023-05-09·CVSS 7.5
CVE-2023-2295 [HIGH] CWE-400 libreswan: Regression of CVE-2023-30570 fixes in the Red Hat Enterprise Linux
libreswan: Regression of CVE-2023-30570 fixes in the Red Hat Enterprise Linux
A vulnerability was found in the libreswan library. This security issue occurs when an IKEv1 Aggressive Mode packet is received with only unacceptable crypto algorithms, and the response packet is not sent with a zero responder SPI. When a subsequent packet is received where the sender reuses the libreswan responder SPI as its own initiator SPI, the pluto daemon state machine crashes. No remote code execution is possible. This CVE exists because of a CVE-2023-30570 security regression for libreswan package in Red Hat Enterprise Linux 8.8 and Red Hat Enterprise Linux 9.2.
A vulnerability was found in the libreswan library. This security issue occurs when an IKEv1 Aggressive Mode packet is received with only unac
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/errata/RHSA-2023:3107https://access.redhat.com/errata/RHSA-2023:3148https://access.redhat.com/security/cve/CVE-2023-2295https://bugzilla.redhat.com/show_bug.cgi?id=2189777https://access.redhat.com/errata/RHSA-2023:3107https://access.redhat.com/errata/RHSA-2023:3148https://access.redhat.com/security/cve/CVE-2023-2295https://bugzilla.redhat.com/show_bug.cgi?id=2189777
2023-05-17
Published