CVE-2023-30570: High severity libreswan vulnerability
pluto in Libreswan before 4.11 allows a denial of service (responder SPI mishandling and daemon crash) via unauthenticated IKEv1 Aggressive Mode packets. The earliest affected version is 3.28.
Other sources
When an IKEv1 Aggressive Mode packet is received with only unacceptable crypto algorithms, the response packet is not sent with a zero responder SPI. When a subsequent packet is received where the sender re-uses the libreswan responder SPI as its own initiator SPI, the pluto daemon state machine crashes. No remote code execution is possible.
https://github.com/libreswan/libreswan/issues/1039
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-30570?
CVE-2023-30570 is a vulnerability in Libreswan that allows a denial of service via unauthenticated IKEv1 Aggressive Mode packets.
What is the severity of CVE-2023-30570?
CVE-2023-30570 has a severity value of 7 (high).
How does CVE-2023-30570 affect Libreswan?
CVE-2023-30570 affects Libreswan versions before 4.11.
How can CVE-2023-30570 be exploited?
CVE-2023-30570 can be exploited by sending unauthenticated IKEv1 Aggressive Mode packets.
Is there a fix for CVE-2023-30570?
Yes, updating Libreswan to version 4.11 or later will fix CVE-2023-30570.