Insecure IPsec transport encryption in Cilium
Vulnerability Description
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Users of IPsec transparent encryption in Cilium may be vulnerable to cryptographic attacks that render the transparent encryption ineffective. In particular, Cilium is vulnerable to chosen plaintext, key recovery, replay attacks by a man-in-the-middle attacker. These attacks are possible due to an ESP sequence number collision when multiple nodes are configured with the same key. Fixed versions of Cilium use unique keys for each IPsec tunnel established between nodes, resolving all of the above attacks. This vulnerability is fixed in 1.13.13, 1.14.9, and 1.15.3.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-28860
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/cilium/cilium/security/advisories/GHSA-pwqm-x5x6-5586
- https://github.com/cilium/cilium/commit/311fbce5280491cddceab178d83b06fa23688c72
- https://github.com/cilium/cilium/commit/a1742b478306fa256cd27df1039dfae0537b4149
- https://github.com/cilium/cilium/commit/a652c123331852cca90c74202f993d4170fd37fa
- https://docs.cilium.io/en/stable/security/network/encryption-ipsec
More from cilium
View All →Affected Vendor
cilium
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.