[strongSwan] Strongswan responds to scan attack

Tobias Brunner tobias at strongswan.org
Thu Dec 6 09:42:09 CET 2018


Hi Naveen,

> The vulnerability is : ISAKMP endpoint allows short key lengths or
> insecure encryption algorithms to be negotiated. This could allow remote
> attackers to compromise the confidentiality and integrity of the data by
> decrypting and modifying individual ESP and AH packets. 

I don't understand what exactly you are referring to.  How is the above
related to responding to unsolicited IKE requests?

Regards,
Tobias



More information about the Users mailing list