Revision Date: | 2022-09-02 | Version: | 1 |
Title: | CVE-2018-5389 |
Description: |
The Internet Key Exchange v1 main mode is vulnerable to offline dictionary or brute force attacks. Reusing a key pair across different versions and modes of IKE could lead to cross-protocol authentication bypasses. It is well known, that the aggressive mode of IKEv1 PSK is vulnerable to offline dictionary or brute force attacks. For the main mode, however, only an online attack against PSK authentication was thought to be feasible. This vulnerability could allow an attacker to recover a weak Pre-Shared Key or enable the impersonation of a victim host or network.
|
Family: | unix | Class: | vulnerability |
Status: | | Reference(s): | Mitre CVE-2018-5389 SUSE CVE-2018-5389
|
Platform(s): | SUSE CaaS Platform 4.5 SUSE Enterprise Storage 7 SUSE Linux Enterprise Desktop 12 SP3 SUSE Linux Enterprise Desktop 15 SUSE Linux Enterprise Desktop 15 SP3 SUSE Linux Enterprise Desktop 15 SP4 SUSE Linux Enterprise High Performance Computing 15 SUSE Linux Enterprise High Performance Computing 15 SP3 SUSE Linux Enterprise High Performance Computing 15 SP4 SUSE Linux Enterprise Module for Basesystem 15 SUSE Linux Enterprise Module for Basesystem 15 SP3 SUSE Linux Enterprise Module for Basesystem 15 SP4 SUSE Linux Enterprise Real Time 15 SP2 SUSE Linux Enterprise Server 12 SP3 SUSE Linux Enterprise Server 15 SUSE Linux Enterprise Server 15 SP3 SUSE Linux Enterprise Server 15 SP4 SUSE Linux Enterprise Server for SAP Applications 15 SUSE Linux Enterprise Server for SAP Applications 15 SP2 SUSE Linux Enterprise Server for SAP Applications 15 SP3 SUSE Linux Enterprise Server for SAP Applications 15 SP4 SUSE Linux Enterprise Storage 7.1 SUSE Linux Enterprise Workstation Extension 15 SP3 SUSE Linux Enterprise Workstation Extension 15 SP4 SUSE Manager Proxy 4.1 SUSE Manager Proxy 4.2 SUSE Manager Proxy 4.3 SUSE Manager Retail Branch Server 4.1 SUSE Manager Retail Branch Server 4.2 SUSE Manager Retail Branch Server 4.3 SUSE Manager Server 4.1 SUSE Manager Server 4.2 SUSE Manager Server 4.3
| Product(s): | |
Definition Synopsis |
SUSE Linux Enterprise Desktop 12 SP3 is installed AND strongswan is affected
|
Definition Synopsis |
Release Information
SUSE CaaS Platform 4.5 is installed
AND strongswan is not affected
OR Package Information
SUSE Linux Enterprise Server for SAP Applications 15 SP2 is installed
AND
strongswan is not affected
OR strongswan-doc is not affected
OR strongswan-hmac is not affected
OR strongswan-ipsec is not affected
OR strongswan-libs0 is not affected
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP3 is installed
AND strongswan is affected
|
Definition Synopsis |
Release Information
SUSE Linux Enterprise Desktop 15 SP3 is installed
OR SUSE Linux Enterprise Server 15 SP3 is installed
OR SUSE Linux Enterprise Server for SAP Applications 15 SP3 is installed
OR SUSE Linux Enterprise Workstation Extension 15 SP3 is installed
AND strongswan-nm is not affected
OR Package Information
SUSE Linux Enterprise Desktop 15 SP3 is installed
OR SUSE Linux Enterprise High Performance Computing 15 SP3 is installed
OR SUSE Linux Enterprise Module for Basesystem 15 SP3 is installed
OR SUSE Linux Enterprise Server 15 SP3 is installed
OR SUSE Linux Enterprise Server for SAP Applications 15 SP3 is installed
OR SUSE Linux Enterprise Storage 7.1 is installed
OR SUSE Manager Proxy 4.2 is installed
OR SUSE Manager Retail Branch Server 4.2 is installed
OR SUSE Manager Server 4.2 is installed
AND
strongswan is not affected
OR strongswan-doc is not affected
OR strongswan-hmac is not affected
OR strongswan-ipsec is not affected
OR strongswan-libs0 is not affected
|
Definition Synopsis |
Release Information
SUSE Linux Enterprise Desktop 15 is installed
OR SUSE Linux Enterprise High Performance Computing 15 is installed
OR SUSE Linux Enterprise Module for Basesystem 15 is installed
OR SUSE Linux Enterprise Server 15 is installed
OR SUSE Linux Enterprise Server for SAP Applications 15 is installed
AND strongswan is not affected
OR Package Information
SUSE Linux Enterprise Desktop 15 SP3 is installed
OR SUSE Linux Enterprise Desktop 15 SP4 is installed
OR SUSE Linux Enterprise High Performance Computing 15 SP3 is installed
OR SUSE Linux Enterprise High Performance Computing 15 SP4 is installed
OR SUSE Linux Enterprise Module for Basesystem 15 SP3 is installed
OR SUSE Linux Enterprise Module for Basesystem 15 SP4 is installed
OR SUSE Linux Enterprise Server 15 SP3 is installed
OR SUSE Linux Enterprise Server 15 SP4 is installed
OR SUSE Linux Enterprise Server for SAP Applications 15 SP3 is installed
OR SUSE Linux Enterprise Server for SAP Applications 15 SP4 is installed
OR SUSE Linux Enterprise Storage 7.1 is installed
OR SUSE Manager Proxy 4.2 is installed
OR SUSE Manager Proxy 4.3 is installed
OR SUSE Manager Retail Branch Server 4.2 is installed
OR SUSE Manager Retail Branch Server 4.3 is installed
OR SUSE Manager Server 4.2 is installed
OR SUSE Manager Server 4.3 is installed
AND
strongswan is not affected
OR strongswan-doc is not affected
OR strongswan-hmac is not affected
OR strongswan-ipsec is not affected
OR strongswan-libs0 is not affected
|
Definition Synopsis |
Release Information
SUSE Linux Enterprise Real Time 15 SP2 is installed
AND strongswan is not affected
OR Package Information
SUSE Linux Enterprise Server for SAP Applications 15 SP2 is installed
AND
strongswan is not affected
OR strongswan-doc is not affected
OR strongswan-hmac is not affected
OR strongswan-ipsec is not affected
OR strongswan-libs0 is not affected
|
Definition Synopsis |
Release Information
SUSE Linux Enterprise Real Time 15 SP2 is installed
OR SUSE Linux Enterprise Server for SAP Applications 15 SP2 is installed
OR SUSE Manager Proxy 4.1 is installed
OR SUSE Manager Retail Branch Server 4.1 is installed
OR SUSE Manager Server 4.1 is installed
AND Package Information
strongswan is not affected
OR strongswan-doc is not affected
OR strongswan-hmac is not affected
OR strongswan-ipsec is not affected
OR strongswan-libs0 is not affected
|
Definition Synopsis |
Release Information
SUSE Linux Enterprise Desktop 15 SP3 is installed
OR SUSE Linux Enterprise Server 15 SP3 is installed
OR SUSE Linux Enterprise Server for SAP Applications 15 SP3 is installed
OR SUSE Linux Enterprise Workstation Extension 15 SP3 is installed
AND strongswan-nm is not affected
OR Package Information
SUSE Enterprise Storage 7 is installed
OR SUSE Linux Enterprise Desktop 15 SP3 is installed
OR SUSE Linux Enterprise High Performance Computing 15 SP3 is installed
OR SUSE Linux Enterprise Module for Basesystem 15 SP3 is installed
OR SUSE Linux Enterprise Real Time 15 SP2 is installed
OR SUSE Linux Enterprise Server 15 SP3 is installed
OR SUSE Linux Enterprise Server for SAP Applications 15 SP2 is installed
OR SUSE Linux Enterprise Server for SAP Applications 15 SP3 is installed
OR SUSE Linux Enterprise Storage 7.1 is installed
OR SUSE Manager Proxy 4.2 is installed
OR SUSE Manager Retail Branch Server 4.2 is installed
OR SUSE Manager Server 4.2 is installed
AND
strongswan is not affected
OR strongswan-doc is not affected
OR strongswan-hmac is not affected
OR strongswan-ipsec is not affected
OR strongswan-libs0 is not affected
|
Definition Synopsis |
Release Information
SUSE Linux Enterprise Desktop 15 SP4 is installed
OR SUSE Linux Enterprise Server 15 SP4 is installed
OR SUSE Linux Enterprise Server for SAP Applications 15 SP4 is installed
OR SUSE Linux Enterprise Workstation Extension 15 SP4 is installed
AND strongswan-nm is not affected
OR Package Information
SUSE Linux Enterprise Desktop 15 SP4 is installed
OR SUSE Linux Enterprise High Performance Computing 15 SP4 is installed
OR SUSE Linux Enterprise Module for Basesystem 15 SP4 is installed
OR SUSE Linux Enterprise Server 15 SP4 is installed
OR SUSE Linux Enterprise Server for SAP Applications 15 SP4 is installed
OR SUSE Manager Proxy 4.3 is installed
OR SUSE Manager Retail Branch Server 4.3 is installed
OR SUSE Manager Server 4.3 is installed
AND
strongswan is not affected
OR strongswan-doc is not affected
OR strongswan-hmac is not affected
OR strongswan-ipsec is not affected
OR strongswan-libs0 is not affected
|