openswan: Improper signature verification in try_RSA_signature_v2() fucntion for RSASSA-PKCS1-v1_5 signature scheme
Published Sep 26, 2018
7.5
HIGHCVSS 3.0
EPSS 1.52%
Description
In verify_signed_hash() in lib/liboswkeys/signatures.c in Openswan before 2.6.50.1, the RSA implementation does not verify the value of padding string during PKCS#1 v1.5 signature verification. Consequently, a remote attacker can forge signatures when small public exponents are being used. IKEv2 signature verification is affected when RAW RSA keys are used.
Affected products
No data.
No data.
Red Hat Enterprise Linux 5
openswan
Not affected
Red Hat Enterprise Linux 6
openswan
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | openswan | Not affected | n/a |
| Red Hat Enterprise Linux 6 | openswan | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This flaw only affects openswan versions compiled without NSS. When NSS is used as cryptographic library, the RSA routines from NSS are used instead of the custom openswan RSA code that contains the vulnerability. Red Hat Enterprise Linux has only ever shipped with NSS enabled openswan versions, so no Red Hat products are vulnerable to this bug.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
1 other source (Red Hat) ▾
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
AV:N/AC:L/Au:N/C:N/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Table of values (12 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 1.52% (0.01522) | 73.71th | v5 (v2026.06.15) |
| Sep 20, 2026 | 1.52% (0.01522) | 73.47th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.27% (0.00268) | 68.08th | v3 (v2023.03.01) |
| May 15, 2024 | 0.27% (0.00268) | 67.59th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.38% (0.00375) | 71.99th | v3 (v2023.03.01) |
| Sep 20, 2023 | 0.38% (0.00375) | 69.48th | v3 (v2023.03.01) |
| Sep 3, 2023 | 0.36% (0.00358) | 68.63th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.33% (0.00325) | 66.06th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.14% (0.01136) | 59.45th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.14% (0.01136) | 34.23th | v2 (v2022.01.01) |
| Feb 3, 2022 | 1.05% (0.01046) | 28.66th | v5 (v2026.06.15) |
| Apr 14, 2021 | 1.05% (0.01046) | 0.00th | v1 |
References (7)
- https://access.redhat.com/security/cve/CVE-2018-15836 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1618861 Issue Tracking
- https://github.com/xelerance/Openswan/commit/0b460be9e287fd335c8ce58129c67bf06065ef51 x_refsource_CONFIRMPatchVendor Advisory
- https://github.com/xelerance/Openswan/commit/9eaa6c2a823c1d2b58913506a15f9474bf857a3d x_refsource_CONFIRMPatchVendor Advisory
- https://lists.openswan.org/pipermail/users/2018-August/023761.html mailing-listx_refsource_MLISTRelease NotesVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-15836
- https://www.cve.org/CVERecord?id=CVE-2018-15836
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2018-15836 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1618861 | Issue Tracking | |
| https://github.com/xelerance/Openswan/commit/0b460be9e287fd335c8ce58129c67bf06065ef51 | x_refsource_CONFIRMPatchVendor Advisory | |
| https://github.com/xelerance/Openswan/commit/9eaa6c2a823c1d2b58913506a15f9474bf857a3d | x_refsource_CONFIRMPatchVendor Advisory | |
| https://lists.openswan.org/pipermail/users/2018-August/023761.html | mailing-listx_refsource_MLISTRelease NotesVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-15836 | ||
| https://www.cve.org/CVERecord?id=CVE-2018-15836 |
Change history (0)
No recorded changes yet.