CVE-2023-30570: Libreswan

High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.

pluto in Libreswan before 4.11 allows a denial of service (responder SPI mishandling and daemon crash) via unauthenticated IKEv1 Aggressive Mode packets. The earliest affected version is 3.28.

Affected products

  • Libreswan Libreswan: from 3.28, up to and including 4.10

Published 2023-05-29. Last modified 2026-06-17.