Xelerance develops Openswan, a widely deployed open-source IPsec implementation used in VPN and secure networking deployments, with a modestly represented vulnerability profile reflecting its specialized infrastructure role. The vendor's disclosed weaknesses center on input validation, OS command injection, memory-bounds violations, and code-injection issues characteristic of C-based network protocol implementations, and the exposure has a moderate tendency toward public exploit availability. Current severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xelerance over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-15836HIGH In verify_signed_hash() in lib/liboswkeys/signatures.c in Openswan before 2.6.50.1, the RSA implementation does not verify the value of padding string during PKCS#1 v1.5 signature | Sep 26, 2018 | 7.5 | 24 | NO | NO |
CVE-2013-2053MEDIUM Buffer overflow in the atodn function in Openswan before 2.6.39, when Opportunistic Encryption is enabled and an RSA key is being used, allows remote attackers to cause a denial of | Jul 9, 2013 | 6.8 | 24 | NO | NO |
CVE-2005-0162HIGH Stack-based buffer overflow in the get_internal_addresses function in the pluto application for Openswan 1.x before 1.0.9, and Openswan 2.x before 2.3.0, when compiled with XAUTH a | Jan 26, 2005 | 7.2 | 24 | NO | NO |
CVE-2010-3308MEDIUM Buffer overflow in programs/pluto/xauth.c in the client in Openswan 2.6.26 through 2.6.28 might allow remote authenticated gateways to execute arbitrary code or cause a denial of s | Oct 5, 2010 | 6.5 | 22 | NO | NO |
CVE-2010-3302MEDIUM Buffer overflow in programs/pluto/xauth.c in the client in Openswan 2.6.25 through 2.6.28 might allow remote authenticated gateways to execute arbitrary code or cause a denial of s | Oct 5, 2010 | 6.5 | 22 | NO | NO |
CVE-2005-3671HIGH The Internet Key Exchange version 1 (IKEv1) implementation in Openswan 2 (openswan-2) before 2.4.4, and freeswan in SUSE LINUX 9.1 before 2.04_1.5.4-1.23, allow remote attackers to | Nov 18, 2005 | 7.8 | 22 | NO | NO |
CVE-2008-4190MEDIUM The IPSEC livetest tool in Openswan 2.4.12 and earlier, and 2.6.x through 2.6.16, allows local users to overwrite arbitrary files and execute arbitrary code via a symlink attack on | Sep 24, 2008 | 4.4 | 21 | NO | YES |
CVE-2010-3753MEDIUM programs/pluto/xauth.c in the client in Openswan 2.6.26 through 2.6.28 allows remote authenticated gateways to execute arbitrary commands via shell metacharacters in the cisco_bann | Oct 5, 2010 | 6.5 | 20 | NO | NO |
CVE-2010-3752MEDIUM programs/pluto/xauth.c in the client in Openswan 2.6.25 through 2.6.28 allows remote authenticated gateways to execute arbitrary commands via shell metacharacters in (1) cisco_dns_ | Oct 5, 2010 | 6.5 | 20 | NO | NO |
CVE-2014-2037MEDIUM Openswan 2.6.40 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon restart) via IKEv2 packets that lack expected payloads. NOTE: this vu | Nov 26, 2014 | 5.0 | 19 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xelerance.
Media articles that mention a CVE ID that affects a product developed by Xelerance — matched by CVE ID, not by vendor name.