IKEv1 default AH/ESP responder can cause libreswan to abort and restart
Vulnerability Description
The Libreswan Project was notified of an issue causing libreswan to restart when using IKEv1 without specifying an esp= line. When the peer requests AES-GMAC, libreswan's default proposal handler causes an assertion failure and crashes and restarts. IKEv2 connections are not affected.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-3652
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- github user X1AOxiang
References
More from The Libreswan Project (www.libreswan.org)
View All →Affected Vendor
The Libreswan Project (www.libreswan.org)
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.