Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
strongSwan 4.3.5 through 5.0.3, when using the OpenSSL plugin for ECDSA signature verification, allows remote attackers to authenticate as other users via an invalid signature.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
strongSwan OpenSSL插件身份验证绕过漏洞
Vulnerability Description
strongSwan是瑞士软件开发者Andreas Steffen所维护的一套Linux平台使用的开源的基于IPsec的VPN解决方案。该方案包含X.509公开密钥证书、安全储存私钥、智能卡等认证机制。 strongSwan 4.3.5至5.0.3版本中存在漏洞。当ECDSA签名验证使用OpenSSL插件时,远程攻击者可通过非法的签名利用该漏洞作为其他用户进行身份验证。
CVSS Information
N/A
Vulnerability Type
N/A