CVE-2023-30570
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published May 29, 2023
Updated: Jan 14, 2025
CWE ID 400
Summary
CVE-2023-30570 is a newly disclosed vulnerability affecting Pluto in Libreswan before version 4.11. This issue permits a denial of service attack through unauthenticated IKEv1 Aggressive Mode packets. The flaw is due to responder SPI mishandling, leading to a daemon crash. Systems running Pluto version 3.28 or earlier are at risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Libreswan