← Vulnerability feed

Vulnerability record · CVE-2004-0590 · published 6 December 2004

CVE-2004-0590: Frees wan vulnerability

FFrees Wan · Frees Wan

FreeS/WAN 1.x and 2.x, and other related products including superfreeswan 1.x, openswan 1.x before 1.0.6, openswan 2.x before 2.1.4, and strongSwan before 2.1.3, allows remote attackers to authenticate using spoofed PKCS#7 certificates in which a self-signed certificate identifies an alternate Certificate Authority (CA) and spoofed issuer and subject.

10.0 CVSS 2.0 High EPSS 2.8% · top 13.9%
10.0CVSS 2.0 base score
2.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
8References
16 Jun 2026Last modified by NVD

Description

FreeS/WAN 1.x and 2.x, and other related products including superfreeswan 1.x, openswan 1.x before 1.0.6, openswan 2.x before 2.1.4, and strongSwan before 2.1.3, allows remote attackers to authenticate using spoofed PKCS#7 certificates in which a self-signed certificate identifies an alternate Certificate Authority (CA) and spoofed issuer and subject.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2004-0590 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-41913Strongswan classic buffer overflow vulnerabilitystrongSwan before 5.9.12 has a buffer overflow and possible unauthenticated remote code execution via a DH public value that exceeds the internal buf…EPSS 2.3%9.8CVE-2023-26463Strongswan improper certificate validation vulnerabilitystrongSwan 5.9.8 and 5.9.9 potentially allows remote code execution because it uses a variable named "public" for two different purposes within the s…EPSS 2.3%9.8CVE-2015-3991Strongswan vulnerabilitystrongSwan 5.2.2 and 5.3.0 allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code.EPSS 4.6%9.1CVE-2021-45079Strongswan null pointer dereference vulnerabilityIn strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticating the client and (in the ca…EPSS 2.8%7.8CVE-2005-3671Frees wan vulnerabilityThe Internet Key Exchange version 1 (IKEv1) implementation in Openswan 2 (openswan-2) before 2.4.4, and freeswan in SUSE LINUX 9.1 before 2.04_1.5.4-…EPSS 7.5%7.5CVE-2026-78130Strongswan null pointer dereference vulnerabilitystrongSwan 4.2.0 through 6.0.7 has a NULL pointer dereference in the x509 plugin's attribute certificate parser.EPSS 0.32%7.5CVE-2026-78132Strongswan vulnerabilitystrongSwan 5.1.3 through 6.0.7 has an infinite loop in the x509 plugin's attribute certificate parser for ietfAttrSyntax.EPSS 0.32%7.5CVE-2026-78133Strongswan use after free vulnerabilitylibcharon in strongSwan 6.0.0 through 6.0.7 has a use-after-free in IKEv2 rekeying collision handling.EPSS 0.43%

Source: NIST National Vulnerability Database (record CVE-2004-0590), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.