Strongswan

Strongswan

51 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.34%
  • Veröffentlicht 11.09.2026 02:07:28
  • Zuletzt bearbeitet 16.09.2026 19:37:30

libcharon in strongSwan 5.9.7 through 6.0.7 mishandles behavioral workflow in the IKEv2 state machine. Because CREATE_CHILD_SA requests are mishandled, there can be an authentication bypass.

  • EPSS 0.32%
  • Veröffentlicht 11.09.2026 02:00:46
  • Zuletzt bearbeitet 14.09.2026 20:06:44

strongSwan 4.5.0 through 6.0.7 has Incorrect Access Control in the eap-ttls and eap-peap plugins because there can be a missing or mismatched inner EAP identity.

  • EPSS 0.42%
  • Veröffentlicht 11.09.2026 01:52:30
  • Zuletzt bearbeitet 14.09.2026 20:07:44

libcharon in strongSwan 6.0.0 through 6.0.7 has a use-after-free in IKEv2 rekeying collision handling.

  • EPSS 0.31%
  • Veröffentlicht 11.09.2026 01:49:15
  • Zuletzt bearbeitet 14.09.2026 20:08:12

strongSwan 5.1.3 through 6.0.7 has an infinite loop in the x509 plugin's attribute certificate parser for ietfAttrSyntax.

  • EPSS 0.23%
  • Veröffentlicht 11.09.2026 01:45:58
  • Zuletzt bearbeitet 14.09.2026 20:08:24

strongSwan 4.2.0 through 6.0.7 has a missing release of memory after its effective lifetime in the x509 plugin's attribute certificate parser.

  • EPSS 0.31%
  • Veröffentlicht 11.09.2026 01:43:43
  • Zuletzt bearbeitet 15.09.2026 16:17:24

strongSwan 4.2.0 through 6.0.7 has a NULL pointer dereference in the x509 plugin's attribute certificate parser.

  • EPSS 0.41%
  • Veröffentlicht 11.09.2026 01:40:01
  • Zuletzt bearbeitet 14.09.2026 20:08:56

strongSwan 4.6.2 through 6.0.7 has an infinite loop in PKCS#5 decryption.

  • EPSS 0.35%
  • Veröffentlicht 11.09.2026 01:37:05
  • Zuletzt bearbeitet 14.09.2026 20:09:10

libcharon in strongSwan 4.1.2 through 6.0.7 has a missing release of memory after its effective lifetime in the IKE message parser.

  • EPSS 0.41%
  • Veröffentlicht 11.09.2026 01:33:50
  • Zuletzt bearbeitet 14.09.2026 20:09:26

strongSwan 4.1.10 through 6.0.7 allows a NULL pointer dereference in the eap-aka plugin.

  • EPSS 0.19%
  • Veröffentlicht 11.09.2026 01:30:47
  • Zuletzt bearbeitet 14.09.2026 20:09:47

strongSwan 5.0.2 through 6.0.7 allows PKCS#7 certificate enumeration in the openssl plugin that leads to a lack of release of memory after its effective lifetime.