Cyber Resilience

CVE-2023-38710

Libreswan 3.20 – 4.12

Published
25 August 2023
Modified
21 November 2024
CVSS Score v3.1 6.5
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Score 0.0081 54th percentile
Risk Priority 52 floored blend · peak EPSS

Summary

CVE-2023-38710 is a medium-severity an unspecified weakness vulnerability in Libreswan Libreswan. Its CVSS base score is 6.5 (Medium).

Operationally, ranked in the top 46% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

An issue was discovered in Libreswan before 4.12. When an IKEv2 Child SA REKEY packet contains an invalid IPsec protocol ID number of 0 or 1, an error notify INVALID_SPI is sent back. The notify payload's protocol ID is copied…

more

from the incoming packet, but the code that verifies outgoing packets fails an assertion that the protocol ID must be ESP (2) or AH(3) and causes the pluto daemon to crash and restart. NOTE: the earliest affected version is 3.20.

CWE(s)

Related Threats

CVEs Like This One

CVE-2023-30570Same product: Libreswan Libreswan
CVE-2023-38711Same product: Libreswan Libreswan
CVE-2026-50721Same product: Libreswan Libreswan
CVE-2026-12413Same product: Libreswan Libreswan
CVE-2023-38712Same product: Libreswan Libreswan
CVE-2024-3652Same product: Libreswan Libreswan
CVE-2026-50722Same product: Libreswan Libreswan
CVE-2023-23009Same product: Libreswan Libreswan
CVE-2023-2295Same product: Libreswan Libreswan

Affected Assets

libreswan
libreswan
3.20 — 4.12

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References