iked in OpenIKED, as used in OpenBSD through 6.7, allows authentication bypass because ca.c has the wrong logic for checking whether a public key matches.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
https://www.openiked.org/security.html | vendor advisory |
https://github.com/xcllnt/openiked/commits/master | third party advisory patch |
https://ftp.openbsd.org/pub/OpenBSD/patches/6.7/common/014_iked.patch.sig | exploit vendor advisory |
https://github.com/openbsd/src/commit/7afb2d41c6d373cf965285840b85c45011357115 | third party advisory patch |