Openswan

Vendor:

First CVE: Jan 26, 2005 · Active for 21 years

16
Total CVEs
More Total CVEs than 93% of tracked products
1.8
Avg CVEs / Year
Higher CVE frequency than 63% of tracked products
5.7
Avg CVSS
Higher Avg CVSS than 20% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Openswan over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 26, 2005
21 years ago
Most Recent CVE
Jun 12, 2019
2,603 days ago

CVE Severity & Scoring

Openswan16 CVEs
All CVEs353,240 CVEs
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network2 (12.5%)
Unknown14 (87.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (6.3%)
High1 (6.3%)
Unknown14 (87.5%)
User Interaction
None2 (12.5%)
Unknown14 (87.5%)
Required0 (0.0%)
Privileges Required
Low1 (6.3%)
High0 (0.0%)
None1 (6.3%)
Unknown14 (87.5%)

Top CVEs

Signals from CVEs in this product scope (16 CVEs).

16 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In verify_signed_hash() in lib/liboswkeys/signatures.c in Openswan before 2.6.50.1, the RSA implementation does not verify the value of padding string during PKCS#1 v1.5 signature
Sep 26, 20187.524NONO
Buffer overflow in the atodn function in Openswan before 2.6.39, when Opportunistic Encryption is enabled and an RSA key is being used, allows remote attackers to cause a denial of
Jul 9, 20136.824NONO
Stack-based buffer overflow in the get_internal_addresses function in the pluto application for Openswan 1.x before 1.0.9, and Openswan 2.x before 2.3.0, when compiled with XAUTH a
Jan 26, 20057.224NONO
Buffer overflow in programs/pluto/xauth.c in the client in Openswan 2.6.26 through 2.6.28 might allow remote authenticated gateways to execute arbitrary code or cause a denial of s
Oct 5, 20106.522NONO
Buffer overflow in programs/pluto/xauth.c in the client in Openswan 2.6.25 through 2.6.28 might allow remote authenticated gateways to execute arbitrary code or cause a denial of s
Oct 5, 20106.522NONO
The Internet Key Exchange version 1 (IKEv1) implementation in Openswan 2 (openswan-2) before 2.4.4, and freeswan in SUSE LINUX 9.1 before 2.04_1.5.4-1.23, allow remote attackers to
Nov 18, 20057.822NONO
The IPSEC livetest tool in Openswan 2.4.12 and earlier, and 2.6.x through 2.6.16, allows local users to overwrite arbitrary files and execute arbitrary code via a symlink attack on
Sep 24, 20084.421NOYES
programs/pluto/xauth.c in the client in Openswan 2.6.26 through 2.6.28 allows remote authenticated gateways to execute arbitrary commands via shell metacharacters in the cisco_bann
Oct 5, 20106.520NONO
programs/pluto/xauth.c in the client in Openswan 2.6.25 through 2.6.28 allows remote authenticated gateways to execute arbitrary commands via shell metacharacters in (1) cisco_dns_
Oct 5, 20106.520NONO
Openswan 2.6.40 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon restart) via IKEv2 packets that lack expected payloads. NOTE: this vu
Nov 26, 20145.019NONO

Exploit Exposure

Signals from CVEs in this product scope (16 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
6.2% of CVEs· 86th percentile

Social Chatter

Signals from CVEs in this product scope (16 CVEs).

Media Mentions

Signals from CVEs in this product scope (16 CVEs).

Top CNAs Publishing CVEs For Openswan

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.6.4015.02.4%00
2.6.3815.02.7%00
2.6.3725.92.5%00
2.6.3635.32.4%00
2.6.3545.22.4%00
2.6.3445.22.4%00
2.6.3345.22.4%00
2.6.3245.22.4%00
2.6.3145.22.4%00
2.6.3045.22.4%00
2.6.2945.22.4%00
2.6.2876.02.9%00
2.6.2776.02.9%00
2.6.2676.02.9%00
2.6.2555.82.7%00
2.6.2435.32.4%00
2.6.2335.32.4%00
2.6.2235.32.4%00
2.6.2135.32.4%00
2.6.2055.22.5%00