CVE-2018-16152 is a critical vulnerability affecting strongSwan 4.x and 5.x before version 5.7.0, specifically within its GMP-based RSA implementation. This flaw allows a remote attacker to forge PKCS#1 v1.5 signatures by exploiting a weakness in how excess data in the digestAlgorithm.parameters field is handled during verification, particularly when small public exponents are in use. With a CVSS score of 7.5 (High), this vulnerability presents a significant risk of impersonation during IKEv2 authentication due to its network-based attack vector and low attack complexity. While there is no evidence of active exploitation, public exploit code, or significant community discussion, the potential for high integrity impact necessitates prompt patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.0.0, <= 4.6.4CPE matchmatch criteria | cpe:2.3:a:strongswan:strongswan:*:*:*:*:*:*:*:* | ||
>= 5.0.0, < 5.7.0CPE matchmatch criteria | cpe:2.3:a:strongswan:strongswan:*:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
14.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.