First published: Tue Jul 28 2020(Updated: )
iked in OpenIKED, as used in OpenBSD through 6.7, allows authentication bypass because ca.c has the wrong logic for checking whether a public key matches.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Openbsd Openbsd | <=6.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-16088 refers to a vulnerability in the OpenIKED component in OpenBSD through version 6.7, where it allows an authentication bypass due to incorrect logic in the ca.c file.
The severity of CVE-2020-16088 is critical with a severity score of 9.8.
CVE-2020-16088 affects OpenBSD versions up to and including 6.7.
To fix CVE-2020-16088, it is recommended to apply the provided patch from the official OpenBSD website.
You can find more information about CVE-2020-16088 in the provided references: [link to the official OpenBSD patches](https://ftp.openbsd.org/pub/OpenBSD/patches/6.7/common/014_iked.patch.sig) and [link to the commit on GitHub](https://github.com/openbsd/src/commit/7afb2d41c6d373cf965285840b85c45011357115).