CVE-2018-5389
Published Sep 6, 2018
5.9
MEDIUMCVSS 3.0
EPSS 3.04%
Description
The Internet Key Exchange v1 main mode is vulnerable to offline dictionary or brute force attacks. Reusing a key pair across different versions and modes of IKE could lead to cross-protocol authentication bypasses. It is well known, that the aggressive mode of IKEv1 PSK is vulnerable to offline dictionary or brute force attacks. For the main mode, however, only an online attack against PSK authentication was thought to be feasible. This vulnerability could allow an attacker to recover a weak Pre-Shared Key or enable the impersonation of a victim host or network.
Affected products
-
- Version 5.5.1StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| strongSwan | Strongswan | n/a |
|
- 1.0
No data.
Red Hat Enterprise Linux 5
ipsec-tools
Will not fix
Red Hat Enterprise Linux 5
openswan
Will not fix
Red Hat Enterprise Linux 6
libreswan
Will not fix
Red Hat Enterprise Linux 6
openswan
Will not fix
Red Hat Enterprise Linux 7
libreswan
Will not fix
Red Hat Enterprise Linux 8
libreswan
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | ipsec-tools | Will not fix | n/a |
| Red Hat Enterprise Linux 5 | openswan | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | libreswan | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | openswan | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | libreswan | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | libreswan | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
PSK based authentication should only be used when the randomness and confidentially of the shared secret can be guaranteed. PSKs should also not be used as Group Secrets, where the security of the PSK is only as strong as the weakest participant in the group. Public Key or EAP authentication methods should be used whenever possible. If PSK must be used, it is essential to ensure the shared secret has a high degree of randomness and is not derived from a password with low entropy, as specified clearly in the IKEv2 specification in RFC 7296. To use passwords for authentication of IKE/IPsec peers, the IKEv2 protocol supports various methods that are not based on (inherently weak) PSKs and which are not vulnerable to offline dictionary attacks: RFC 5998: EAP-Only Authentication in IKEv2 RFC 6617: Secure Pre-Shared Key (PSK) Authentication for IKE RFC 6631: Password Authenticated Connection Establishment with IKEv2 RFC 6628: Efficient Augmented Password-Only Authentication and Key Exchange for IKEv2 As implementations supporting IKE assume the security of provided PSKs, and no mechanism within the protocol allows for password-stretching, we do not anticipate any software fixes becoming available. The research paper that describes the problems of using weak PSKs also listed another security issue with respect to RSA keys that has different CVE numbers. Libreswan is not vulnerable to those attacks as it requires IKEv1 using either ("Encryption with RSA" (value 5) or "Revised encryption with RSA" (value 6). Both of these modes are not implemented by libreswan.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
AV:N/AC:M/Au:N/C:P/I:N/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v5
Table of values (14 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 3.04% (0.03038) | 87.06th | v5 (v2026.06.15) |
| Jun 15, 2026 | 3.04% (0.03038) | 85.75th | v5 (v2026.06.15) |
| Jul 19, 2024 | 0.31% (0.00310) | 70.29th | v3 (v2023.03.01) |
| Jun 25, 2024 | 0.31% (0.00310) | 70.14th | v3 (v2023.03.01) |
| Aug 31, 2023 | 0.21% (0.00207) | 57.95th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.19% (0.00195) | 55.44th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.02% (0.01018) | 40.69th | v2 (v2022.01.01) |
| Sep 10, 2022 | 1.02% (0.01018) | 38.88th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.02% (0.01018) | 36.86th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.02% (0.01018) | 19.50th | v2 (v2022.01.01) |
| Feb 3, 2022 | 1.04% (0.01040) | 28.32th | v1 |
| Jan 6, 2022 | 1.04% (0.01040) | 27.69th | v1 |
| Sep 1, 2021 | 1.04% (0.01040) | 64.49th | v1 |
| Apr 14, 2021 | 1.04% (0.01040) | 0.00th | v1 |
References (9)
- https://access.redhat.com/security/cve/CVE-2018-5389 Vendor Advisory
- https://blogs.cisco.com/security/great-cipher-but-where-did-you-get-that-key Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1603064 Issue Tracking
- https://my.f5.com/manage/s/article/K42378447
- https://nvd.nist.gov/vuln/detail/CVE-2018-5389
- https://web-in-security.blogspot.com/2018/08/practical-dictionary-attack-on-ipsec-ike.html ExploitThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2018-5389
- https://www.kb.cert.org/vuls/id/857035 Third Party AdvisoryUS Government Resource
- https://www.usenix.org/system/files/conference/usenixsecurity18/sec18-felsch.pdf Third Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2018-5389 | Vendor Advisory | |
| https://blogs.cisco.com/security/great-cipher-but-where-did-you-get-that-key | Third Party Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1603064 | Issue Tracking | |
| https://my.f5.com/manage/s/article/K42378447 | ||
| https://nvd.nist.gov/vuln/detail/CVE-2018-5389 | ||
| https://web-in-security.blogspot.com/2018/08/practical-dictionary-attack-on-ipsec-ike.html | ExploitThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2018-5389 | ||
| https://www.kb.cert.org/vuls/id/857035 | Third Party AdvisoryUS Government Resource | |
| https://www.usenix.org/system/files/conference/usenixsecurity18/sec18-felsch.pdf | Third Party Advisory |
Change history (0)
No recorded changes yet.