IKE: StrongSwan x509 Plugin Denial Of Service

This signature detects attempts to exploit a known vulnerability in strongSwan. Successful exploitation will result in denial-of-service conditions on the target server.

Extended Description

The ASN.1 parser in strongSwan before 5.5.3 improperly handles CHOICE types when the x509 plugin is enabled, which allows remote attackers to cause a denial of service (infinite loop) via a crafted certificate.

Affected Products

Strongswan strongswan

References

BugTraq: 98756

CVE: CVE-2017-9023

Short Name
IKE:STRONGSWAN-PLUGIN-DOS
Severity
Major
Recommended
True
Recommended Action
Drop
Category
IKE
Keywords
CVE-2017-9023 Denial Of Plugin Service StrongSwan bid:98756 x509
Release Date
07/14/2017
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3337
False Positive
Unknown
Vendors

Strongswan

CVSS Score

4.3

Found a potential security threat?