CVE-2013-2944

strongSwan 4.3.5-5.0.3 - Improper Authentication via Invalid ECDSA Signature

Title source: llm
STIX 2.1

Description

strongSwan 4.3.5 through 5.0.3, when using the OpenSSL plugin for ECDSA signature verification, allows remote attackers to authenticate as other users via an invalid signature.

References (7)

Core 7
Core References
Mailing List vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2013-06/msg00121.html
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2013/dsa-2665
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/59580
Mailing List vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2013-05/msg00014.html
Mailing List vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2013-06/msg00010.html

Scores

EPSS 0.0158
EPSS Percentile 72.5%

Details

CWE
CWE-287
Status published
Products (17)
strongswan/strongswan 4.3.5
strongswan/strongswan 4.3.6
strongswan/strongswan 4.3.7
strongswan/strongswan 4.4.0
strongswan/strongswan 4.4.1
strongswan/strongswan 4.5.0
strongswan/strongswan 4.5.1
strongswan/strongswan 4.5.2
strongswan/strongswan 4.5.3
strongswan/strongswan 4.6.0
... and 7 more
Published May 02, 2013
Tracked Since Feb 18, 2026