CVE-2019-10155 PUBLISHED

The Libreswan Project has found a vulnerability in the processing of IKEv1 informational exchange packets which are encrypted and integrity protected using the established IKE SA encryption and integrity keys, but as a receiver, the integrity check value was not verified. This issue affects versions before 3.29.

EPSS 0.23% · 45.2th percentile

Risk Scores

EPSS Score
0.23%
45.2th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSlibreswan0, 3.20-7build1, 3.21-2

Timeline

References

Open in Interactive Console →