Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2017-9022

EPSS 1.35% · P80
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2017-9022

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
The gmp plugin in strongSwan before 5.5.3 does not properly validate RSA public keys before calling mpz_powm_sec, which allows remote peers to cause a denial of service (floating point exception and process crash) via a crafted certificate.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
strongSwan 输入验证错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
strongSwan是瑞士Andreas Steffen软件开发者的一套Linux平台使用的开源的基于IPsec的VPN解决方案。该方案包含X.509公开密钥证书、安全储存私钥、智能卡等认证机制。gmp plugin是其中的一个插件。 strongSwan 5.5.3之前的版本中的gmp插件存在安全漏洞,该漏洞源于在调用mpz_powm_sec之前,程序没有正确的验证RSA公钥。远程攻击者可借助特制的证书利用该漏洞造成拒绝服务(浮点异常和进程崩溃)。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2017-9022

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2017-9022

登录查看更多情报信息。

Same Patch Batch · n/a · 2017-06-08 · 50 CVEs total

CVE-2017-5878Red5 Media Server 安全漏洞
CVE-2017-9518AtMail 跨站请求伪造漏洞
CVE-2017-6639Cisco Prime Data Center Network Manager for Microsoft Windows、Linux和Virtual Appliance平台安全漏
CVE-2017-6640Cisco Prime Data Center Network Manager 安全漏洞
CVE-2017-6648Cisco TelePresence Codec和Collaboration Endpoint软件资源管理错误漏洞
CVE-2017-9516Craft CMS 跨站脚本漏洞
CVE-2017-7180Net Monitor for Employees Pro 代码问题漏洞
CVE-2017-6638Cisco AnyConnect Secure Mobility Client for Windows 权限许可和访问控制问题漏洞
CVE-2017-9023strongSwan ASN.1解析器安全漏洞
CVE-2017-8108Lynis 安全漏洞
CVE-2017-9310QEMU 输入验证错误漏洞
CVE-2015-2800多款华为产品user authentication模块安全漏洞
CVE-2015-2255Huawei AR1220 安全漏洞
CVE-2015-2253Huawei OceanStor UDS 信息泄露漏洞
CVE-2015-2252Huawei OceanStor UDS 代码注入漏洞
CVE-2015-2251Huawei OceanStor UDS DeviceManager 信息泄露漏洞
CVE-2014-8687Seagate Business NAS 安全漏洞
CVE-2014-6031多款F5产品缓冲区错误漏洞
CVE-2014-4843IBM Curam Social Program Management Curam Universal Access 安全漏洞
CVE-2016-4471Red Hat CloudForms ManageIQ 权限许可和访问控制漏洞

Showing top 20 of 50 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2017-9022

No comments yet


Leave a comment