CVE-2019-5613: Freebsd
Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.
In FreeBSD 12.0-RELEASE before 12.0-RELEASE-p13, a missing check in the ipsec packet processor allows reinjection of an old packet to be accepted by the ipsec endpoint. Depending on the higher-level protocol in use over ipsec, this could allow an action to be repeated.
Affected products
- Freebsd Freebsd: version 12.0 only
Published 2020-02-18. Last modified 2026-06-17.