Description
The Libreswan Project was notified of an issue causing libreswan to restart under some IKEv2 retransmit scenarios when a connection is configured to use PreSharedKeys (authby=secret) and the connection cannot find a matching configured secret. When such a connection is automatically added on startup using the auto= keyword, it can cause repeated crashes leading to a Denial of Service.
Published: 2024-03-11
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

This issue is fixed in 4.13, 5.0 and all later versions.


Vendor Workaround

As a workaround, one can place an unguessable long random default secret in /etc/ipsec.secrets, for example using the following command: echo -e "# CVE-2024-2357 workaround : PSK "$(openssl rand -hex 32)"" >> /etc/ipsec.secrets This will ensure a PSK secret is always found, but it will always be wrong, and thus authentication will still properly fail.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-27310 The Libreswan Project was notified of an issue causing libreswan to restart under some IKEv2 retransmit scenarios when a connection is configured to use PreSharedKeys (authby=secret) and the connection cannot find a matching configured secret. When such a connection is automatically added on startup using the auto= keyword, it can cause repeated crashes leading to a Denial of Service.
History

Thu, 13 Feb 2025 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat openshift
CPEs cpe:/a:redhat:openshift:4.15::el9
cpe:/a:redhat:openshift:4.16::el9
cpe:/a:redhat:openshift:4.17::el9
Vendors & Products Redhat openshift

Mon, 02 Dec 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Redhat rhel E4s
CPEs cpe:/a:redhat:rhel_e4s:9.0
Vendors & Products Redhat rhel E4s

Wed, 20 Nov 2024 18:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.0, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Redhat Enterprise Linux Openshift Rhel E4s Rhel Eus
cve-icon MITRE

Status: PUBLISHED

Assigner: libreswan

Published:

Updated: 2025-02-13T17:39:47.355Z

Reserved: 2024-03-09T22:24:12.530Z

Link: CVE-2024-2357

cve-icon Vulnrichment

Updated: 2024-08-01T19:11:53.507Z

cve-icon NVD

Status : Deferred

Published: 2024-03-11T20:15:07.867

Modified: 2026-04-15T00:35:42.020

Link: CVE-2024-2357

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-03-11T00:00:00Z

Links: CVE-2024-2357 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses