pluto in Libreswan before 4.11 allows a denial of service (responder SPI mishandling and daemon crash) via unauthenticated IKEv1 Aggressive Mode packets. The earliest affected version is 3.28.
2023-05-29T00:15:09.820
2025-01-14T19:15:29.790
Modified
CVSSv3.1: 7.5 (HIGH)