Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-15522
HistoryJan 13, 2022 - 12:00 a.m.

Libreswan Code Issue Vulnerability (CNVD-2022-15522)

2022-01-1300:00:00
China National Vulnerability Database
www.cnvd.org.cn
15
libreswan
ipsec
code issue
vulnerability
ikev1
logging operation
pluto daemon

EPSS

0.02

Percentile

89.1%

Libreswan is an IPsec implementation similar to Openswan, which is mainly used to ensure security, integrity issues in data transmission. libreswan has a code issue vulnerability that can be exploited by an attacker to send specially crafted IKEv1 packets to an application, triggering a logging operation during a denied IKEv1 packet NULL pointer dereference error and crash the pluto daemon.