← Back

CVE-2022-40617

nvd nist
Published: Oct 31, 2022Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a crafted end-entity (and intermediate CA) certificate that contains a CRL/OCSP URL that points to a server (under the attacker's control) that doesn't properly respond but (for example) just does nothing after the initial TCP handshake, or sends an excessive amount of application data.

Affected (12)

Show all products
1 product
Strongswan
1 product
Ubuntu Linux
1 product
Debian Linux
1 product
Fedora
1 product
Stormshield Network Security
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 5.9.8
Configuration B
5 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 14.04
Version 16.04
Version 18.04
Version 20.04
Version 22.04
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 10.0
Version 11.0
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 37
Configuration E
3 vulnerable
Vulnerable SoftwareAffected Versions
Stormshield
From 3.11.1 to 3.11.20
From 4.3.1 to 4.3.15
From 4.5.1 to 4.6.0

Timeline

No history available yet.