← Back

CVE-2014-2338

nvd nist
Published: Apr 16, 2014Modified: May 6, 2026

JSON object

Loading...
6.4
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:N
Exploitability: 10.0 / Impact: 4.9
Source: NVD

Description

IKEv2 in strongSwan 4.0.7 before 5.1.3 allows remote attackers to bypass authentication by rekeying an IKE_SA during (1) initiation or (2) re-authentication, which triggers the IKE_SA state to be set to established.

Affected (57)

1 product
Strongswan
Configuration A
57 vulnerable
Vulnerable SoftwareAffected Versions
Strongswan
Version 4.0.7
Version 4.1.0
Version 4.1.10
Version 4.1.11
Version 4.1.1
Version 4.1.2
Version 4.1.3
Version 4.1.4
Version 4.1.5
Version 4.1.6
Version 4.1.7
Version 4.1.8
Version 4.1.9
Version 4.2.0
Version 4.2.10
Version 4.2.11
Version 4.2.12
Version 4.2.13
Version 4.2.14
Version 4.2.15
Version 4.2.16
Version 4.2.1
Version 4.2.2
Version 4.2.3
Version 4.2.4
Version 4.2.5
Version 4.2.6
Version 4.2.7
Version 4.2.8
Version 4.2.9
Version 4.3.0
Version 4.3.1
Version 4.3.2
Version 4.3.3
Version 4.3.4
Version 4.3.5
Version 4.3.6
Version 4.3.7
Version 4.4.0
Version 4.4.1
Version 4.5.0
Version 4.5.1
Version 4.5.2
Version 4.5.3
Version 4.6.0
Version 4.6.1
Version 4.6.2
Version 4.6.3
Version 4.6.4
Version 5.0.0
Version 5.0.1
Version 5.0.2
Version 5.0.3
Version 5.0.4
Version 5.1.0
Version 5.1.1
Version 5.1.2

Timeline

No history available yet.