CVE-2015-3204: Libreswan
Medium severity, CVSS 5.0. EPSS: 2.6% chance of exploitation in the next 30 days.
libreswan 3.9 through 3.12 allows remote attackers to cause a denial of service (daemon restart) via an IKEv1 packet with (1) unassigned bits set in the IPSEC DOI value or (2) the next payload value set to ISAKMP_NEXT_SAK.
Affected products
- Libreswan Libreswan: version 3.9 only; version 3.10 only; version 3.11 only; version 3.12 only
Published 2015-07-01. Last modified 2026-06-17.