In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and 5.x before 5.7.0, the RSA implementation based on GMP does not reject excess data in the digestAlgorithm.parameters field during PKCS#1 v1.5 signature verification. Consequently, a remote attacker can forge signatures when small public exponents are being used, which could lead to impersonation when only an RSA signature is used for IKEv2 authentication. This is a variant of CVE-2006-4790 and CVE-2014-1568.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-strongswan | Oct 5, 2018 | Sep 26, 2018 | |
| Arch Linux | arch-linux-upgrade-latest | Jul 11, 2025 | Sep 26, 2018 | |
| Debian | debian-upgrade-strongswan | Sep 26, 2018 | Sep 24, 2018 | |
| Gentoo Linux | gentoo-linux-upgrade-net-vpn-strongswan | Nov 27, 2018 | Sep 26, 2018 | |
| Huawei Euleros 2_0_sp2 | huawei-euleros-2_0_sp2-upgrade-strongimcv | Feb 22, 2021 | Sep 26, 2018 | |
| Suse | — | suse-upgrade-strongswansuse-upgrade-strongswan-docsuse-upgrade-strongswan-hmacsuse-upgrade-strongswan-ipsecsuse-upgrade-strongswan-libs0suse-upgrade-strongswan-mysqlsuse-upgrade-strongswan-nmsuse-upgrade-strongswan-sqlite | Dec 3, 2019 | Sep 24, 2018 |
| Ubuntu | ubuntu-upgrade-libstrongswanubuntu-upgrade-strongswan | Oct 2, 2018 | Sep 24, 2018 | |
| Vmware Photon_os | vmware-photon_os_update_tdnf | Jan 20, 2025 | Sep 26, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub