Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2014-2338

EPSS 0.32% · P55
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2014-2338

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
IKEv2 in strongSwan 4.0.7 before 5.1.3 allows remote attackers to bypass authentication by rekeying an IKE_SA during (1) initiation or (2) re-authentication, which triggers the IKE_SA state to be set to established.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
strongSwan IKEv2 授权问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
strongSwan是瑞士软件开发者Andreas Steffen所维护的一套Linux平台使用的开源的基于IPsec的VPN解决方案。该方案包含X.509公开密钥证书、安全储存私钥、智能卡等认证机制。 strongSwan 4.0.7至5.1.2版本中的IKEv2存在安全漏洞。远程攻击者可利用该漏洞绕过身份验证。安装actively initiate或re-authenticate IKEv2 IKE_SAs的系统受到影响。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2014-2338

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2014-2338

登录查看更多情报信息。

Same Patch Batch · n/a · 2014-04-16 · 97 CVEs total

CVE-2014-2463Oracle Secure Global Desktop 安全漏洞
CVE-2014-2459Oracle Transportation Management 任意代码执行漏洞
CVE-2014-2457Oracle Supply Chain Oracle Agile Product Lifecycle 安全漏洞
CVE-2014-2452Oracle Fusion Middleware Oracle Access Manager 拒绝服务漏洞
CVE-2014-2451Oracle MySQL Server 拒绝服务漏洞
CVE-2014-2450Oracle MySQL Server 拒绝服务漏洞
CVE-2014-2449Oracle PeopleSoft Enterprise HRMS Talent Acquisition Manager 安全漏洞
CVE-2014-2448Oracle PeopleSoft Enterprise PT PeopleTools 安全漏洞
CVE-2014-2453Oracle Hyperion 安全漏洞
CVE-2014-2461Oracle Transportation Management 安全漏洞
CVE-2014-2460Oracle Transportation Management 安全漏洞
CVE-2014-2464Oracle Agile PLM Framework 安全漏洞
CVE-2014-2465Oracle Agile PLM Framework 安全漏洞
CVE-2014-2466Oracle Agile PLM Framework 安全漏洞
CVE-2014-2467Oracle Agile PLM Framework 安全漏洞
CVE-2014-2468Oracle Siebel CRM 安全漏洞
CVE-2014-2470Oracle WebLogic Server 任意代码执行漏洞
CVE-2014-2471Oracle iLearning 安全漏洞
CVE-2014-0451Oracle Java SE和Java SE Embedded 安全漏洞
CVE-2014-0452Java SE和Java SE Embedded 安全漏洞

Showing top 20 of 97 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2014-2338

No comments yet


Leave a comment