CVE Vulnerabilities

CVE-2019-10155

Improper Validation of Integrity Check Value

Published: Jun 12, 2019 | Modified: Nov 07, 2023
CVSS 3.x
3.1
LOW
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
CVSS 2.x
3.5 LOW
AV:N/AC:M/Au:S/C:N/I:N/A:P
RedHat/V2
RedHat/V3
3.1 LOW
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
Ubuntu
LOW

The Libreswan Project has found a vulnerability in the processing of IKEv1 informational exchange packets which are encrypted and integrity protected using the established IKE SA encryption and integrity keys, but as a receiver, the integrity check value was not verified. This issue affects versions before 3.29.

Weakness

The product does not validate or incorrectly validates the integrity check values or “checksums” of a message. This may prevent it from detecting if the data has been modified or corrupted in transmission.

Affected Software

Name Vendor Start Version End Version
Libreswan Libreswan * 3.29 (excluding)
Strongswan Strongswan * 5.0.0 (excluding)
Openswan Xelerance * *
Red Hat Enterprise Linux 8 RedHat libreswan-0:3.29-6.el8 *
Libreswan Ubuntu bionic *
Libreswan Ubuntu cosmic *
Libreswan Ubuntu devel *
Libreswan Ubuntu disco *
Libreswan Ubuntu eoan *
Libreswan Ubuntu esm-apps/bionic *
Libreswan Ubuntu focal *
Libreswan Ubuntu groovy *
Libreswan Ubuntu hirsute *
Libreswan Ubuntu impish *
Libreswan Ubuntu jammy *
Libreswan Ubuntu kinetic *
Libreswan Ubuntu lunar *
Libreswan Ubuntu mantic *
Libreswan Ubuntu noble *
Libreswan Ubuntu oracular *
Libreswan Ubuntu trusty *
Libreswan Ubuntu upstream *

Potential Mitigations

References