CVE Database
/

CVE-2019-10155

Back to search

CVE-2019-10155

Published: Jun 12, 2019

Modified: Aug 4, 2024

PUBLISHED

CVSS v3.0

3.1

LOW

Description

The Libreswan Project has found a vulnerability in the processing of IKEv1 informational exchange packets which are encrypted and integrity protected using the established IKE SA encryption and integrity keys, but as a receiver, the integrity check value was not verified. This issue affects versions before 3.29.

VendorProductVersions

the libreswan Project

libreswan

affected
3.29

Weaknesses (CWE)

CVSS v3.0 Details

CVSS v3.0 Vector

CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L

Attack Vector

Network

Attack Complexity

High

Privileges Required

Low

User Interaction

None

Scope

Unchanged

Confidentiality

None

Integrity

None

Availability

Low

References

FEDORA-2019-f7fb531958
vendor-advisory
x_refsource_FEDORA
FEDORA-2019-1bd9cfb718
vendor-advisory
x_refsource_FEDORA
RHSA-2019:3391
vendor-advisory
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now