« Volver al listado

CVE-2024-3652

Estado: AnalizadaMedia (6.5)—

The Libreswan Project was notified of an issue causing libreswan to restart when using IKEv1 without specifying an esp= line. When the peer requests AES-GMAC, libreswan's default proposal handler causes an assertion failure and crashes and restarts. IKEv2 connections are not affected.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-3652",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-3652",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-04-11T17:26:47.015453Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "d42dc95b-23f1-4e06-9076-20753a0fb0df",
      "affectedData": [
        {
          "vendor": "The Libreswan Project (www.libreswan.org)",
          "product": "libreswan",
          "versions": [
            {
              "status": "affected",
              "version": "3.22",
              "versionType": "semver",
              "lessThanOrEqual": "4.14"
            },
            {
              "status": "unaffected",
              "version": "5.0"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2024-04-11T02:15:47.790",
  "references": [
    {
      "url": "http://www.openwall.com/lists/oss-security/2024/04/18/2",
      "tags": [
        "Mailing List"
      ],
      "source": "d42dc95b-23f1-4e06-9076-20753a0fb0df"
    },
    {
      "url": "https://libreswan.org/security/CVE-2024-3652",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "d42dc95b-23f1-4e06-9076-20753a0fb0df"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2024/04/18/2",
      "tags": [
        "Mailing List"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://libreswan.org/security/CVE-2024-3652",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-404"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Libreswan Project was notified of an issue causing libreswan to restart when using IKEv1 without specifying an esp= line. When the peer requests AES-GMAC, libreswan's default proposal handler causes an assertion failure and crashes and restarts. IKEv2 connections are not affected."
    },
    {
      "lang": "es",
      "value": "Se notificó a Libreswan Project sobre un problema que provocaba que libreswan se reiniciara al usar IKEv1 sin especificar una línea esp=. Cuando el par solicita AES-GMAC, el controlador de propuestas predeterminado de libreswan provoca un error de aserción, falla y se reinicia. Las conexiones IKEv2 no se ven afectadas."
    }
  ],
  "lastModified": "2026-06-17T07:44:44.500",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:libreswan:libreswan:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DFCF4ECE-E126-47B3-9B03-C420896DAFB3",
              "versionEndExcluding": "4.15",
              "versionStartIncluding": "3.22"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "d42dc95b-23f1-4e06-9076-20753a0fb0df"
}