CVE-2019-5613
Estado: ModificadaCrítica (9.8)—
In FreeBSD 12.0-RELEASE before 12.0-RELEASE-p13, a missing check in the ipsec packet processor allows reinjection of an old packet to be accepted by the ipsec endpoint. Depending on the higher-level protocol in use over ipsec, this could allow an action to be repeated.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.58%
- Percentil entre todas las CVEs puntuadas: 46
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-345
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2019-5613",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "secteam@freebsd.org",
"affectedData": [
{
"vendor": "n/a",
"product": "FreeBSD",
"versions": [
{
"status": "affected",
"version": "12.0 before 12.0-RELEASE-p13"
}
]
}
]
}
],
"published": "2020-02-18T16:15:11.173",
"references": [
{
"url": "https://security.FreeBSD.org/advisories/FreeBSD-SA-20:02.ipsec.asc",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "secteam@freebsd.org"
},
{
"url": "https://security.FreeBSD.org/advisories/FreeBSD-SA-20:02.ipsec.asc",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-345"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In FreeBSD 12.0-RELEASE before 12.0-RELEASE-p13, a missing check in the ipsec packet processor allows reinjection of an old packet to be accepted by the ipsec endpoint. Depending on the higher-level protocol in use over ipsec, this could allow an action to be repeated."
},
{
"lang": "es",
"value": "En FreeBSD versiones 12.0-RELEASE anteriores a 12.0-RELEASE-p13, una falta de comprobación en el procesador de paquetes ipsec, permite que una reinyección de un paquete antiguo sea aceptada por parte del endpoint de ipsec. Dependiendo del protocolo de nivel superior en uso mediante ipsec, esto podría permitir una acción sea repetida."
}
],
"lastModified": "2026-06-17T02:37:56.610",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:freebsd:freebsd:12.0:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "826B53C2-517F-4FC6-92E8-E7FCB24F91B4"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:12.0:p1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "93F10A46-AEF2-4FDD-92D6-0CF07B70F986"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:12.0:p10:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8C7B8FCA-2170-469A-B6D6-2C6AB254F20F"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:12.0:p11:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E94067A1-5C68-4401-A7B6-29B4FE553733"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:12.0:p12:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "87EE567B-7604-41CC-B0A7-B51255D4C240"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:12.0:p2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E1AD57A9-F53A-4E40-966E-F2F50852C5E4"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:12.0:p3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C4029113-130F-4A33-A8A0-BC3E74000378"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:12.0:p4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "46C5A6FD-7BBF-4E84-9895-8EE14DC846E4"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:12.0:p6:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "882669AB-BCFC-4517-A3E9-33D344F1ED0D"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:12.0:p7:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BC3D24FB-50A2-4E37-A479-AF21F8ECD706"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:12.0:p8:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3070787D-76E1-4671-B99D-213F7103B3A2"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:12.0:p9:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0140276F-9C31-4B5C-A5AC-DE0EBB885275"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "secteam@freebsd.org"
}