« Volver al listado

CVE-2026-12413

Estado: AnalizadaAlta (7.5)—

An invalidly formatted IKEv2 fragment causes the Libreswan pluto daemon to crash and restart. Continued exploitation would cause a denial of service. The function reassemble_v2_incoming_fragments() would ignore unknown outer payloads but still store these in a fixed size array msg_digest.digest[PAYLIMIT]. An off-by-one error in the assertion PASSERT(logger, md->digest_roof < elemsof(md->digest)) causes the daemon to abort. No remote code execution is possible. Any configuration that allows IKEv2 connections that do not set fragmentation=no are vulnerable. IKEv1 is not affected.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vector CVSS AV:N/AC:L/PR:N/UI:N permite explotación remota sin privilegios (T1190). Descripción explícita de crash del daemon por envío de fragmentos IKEv2 malformados, causando denegación de servicio (T1499.004 - Application Exhaustion DoS).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-12413",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-12413",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-07-06T18:12:21.499364Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "d42dc95b-23f1-4e06-9076-20753a0fb0df",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "d42dc95b-23f1-4e06-9076-20753a0fb0df",
      "affectedData": [
        {
          "vendor": "The Libreswan Project",
          "product": "libreswan",
          "versions": [
            {
              "status": "affected",
              "version": "4.6",
              "versionType": "semver",
              "lessThanOrEqual": "5.3"
            },
            {
              "status": "unaffected",
              "version": "5.3.1",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-07-02T22:16:42.517",
  "references": [
    {
      "url": "https://libreswan.org/security/CVE-2026-12413/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "d42dc95b-23f1-4e06-9076-20753a0fb0df"
    },
    {
      "url": "https://libreswan.org/security/CVE-2026-12413/CVE-2026-12413.txt",
      "tags": [
        "Vendor Advisory",
        "Mitigation"
      ],
      "source": "d42dc95b-23f1-4e06-9076-20753a0fb0df"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "d42dc95b-23f1-4e06-9076-20753a0fb0df",
      "description": [
        {
          "lang": "en",
          "value": "CWE-193"
        },
        {
          "lang": "en",
          "value": "CWE-617"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An invalidly formatted IKEv2 fragment causes the Libreswan pluto daemon to crash and restart. Continued exploitation would cause a denial of service. The function reassemble_v2_incoming_fragments() would ignore unknown outer payloads but still store these in a fixed size array msg_digest.digest[PAYLIMIT]. An off-by-one error in the assertion PASSERT(logger, md->digest_roof < elemsof(md->digest)) causes the daemon to abort. No remote code execution is possible. Any configuration that allows IKEv2 connections that do not set fragmentation=no are vulnerable. IKEv1 is not affected."
    }
  ],
  "lastModified": "2026-07-08T18:52:42.920",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:libreswan:libreswan:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "535F926A-021B-40BB-929F-618252622EAB",
              "versionEndExcluding": "5.3.1",
              "versionStartIncluding": "4.6"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "d42dc95b-23f1-4e06-9076-20753a0fb0df"
}