CVE-2013-2944: Strongswan
Medium severity, CVSS 4.9. EPSS: 1.6% chance of exploitation in the next 30 days.
strongSwan 4.3.5 through 5.0.3, when using the OpenSSL plugin for ECDSA signature verification, allows remote attackers to authenticate as other users via an invalid signature.
Affected products
- Strongswan Strongswan: version 4.3.5 only; version 4.3.6 only; version 4.3.7 only; version 4.4.0 only; version 4.4.1 only; version 4.5.0 only; …
Published 2013-05-02. Last modified 2026-06-16.