Denial of Service Vulnerability in Pluto IKE Daemon

Denial of Service Vulnerability in Pluto IKE Daemon

CVE-2015-3240 · MEDIUM Severity

AV:N/AC:M/AU:N/C:N/I:N/A:P

The pluto IKE daemon in libreswan before 3.15 and Openswan before 2.6.45, when built with NSS, allows remote attackers to cause a denial of service (assertion failure and daemon restart) via a zero DH g^x value in a KE payload in a IKE packet.

Learn more about our Web Application Penetration Testing UK.