Impact
A malformed X.509 certificate can trigger an assertion failure in the libreswan IPsec daemon. The failure causes the daemon to crash, leading to a loss of availability for any IPsec VPN connections that rely on it. This flaw is characterized as a flow‑control flaw (CWE‑617) stemming from insufficient validation of certificate data, and it manifests as a denial‑of‑service condition for the affected system.
Affected Systems
The flaw affects installations of the libreswan IPsec daemon that accept or process X.509 certificates. Because the affected releases are not specified, any deployment that runs libreswan without the corrective update and performs certificate validation is potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.5 denotes a moderate‑to‑high severity vulnerability. With no EPSS score available, a precise measurement of exploitation probability is lacking, but the nature of the defect indicates that remote attackers could exploit it by initiating or injecting a malformed certificate over an externally reachable IPsec interface. The vulnerability is not listed in CISA's KEV catalog, yet it remains a substantial risk for unpatched systems due to its impact on service availability and the possibility of remote exploitation.
OpenCVE Enrichment