Improper Authentication in strongSwan - CVE-2013-2944

 

Improper Authentication in strongSwan - CVE-2013-2944

Published: May 2, 2013 / Updated: August 11, 2020


Vulnerability identifier: #VU42852
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2013-2944
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote #AU# to read and manipulate data.

strongSwan 4.3.5 through 5.0.3, when using the OpenSSL plugin for ECDSA signature verification, allows remote attackers to authenticate as other users via an invalid signature.


Affected software

strongSwan
Gentoo Linux

How to mitigate CVE-2013-2944

Install update from vendor's website.


External References

Related Security Bulletins