Strongswan

Strongswan

51 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.41%
  • Veröffentlicht 11.09.2026 01:26:21
  • Zuletzt bearbeitet 15.09.2026 16:17:24

strongSwan 5.0.2 through 6.0.7 has an Expired Pointer Dereference in PKCS#7 parsing in the openssl plugin.

  • EPSS 0.67%
  • Veröffentlicht 22.08.2026 22:16:28
  • Zuletzt bearbeitet 09.09.2026 16:04:24

In strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-Identities that result in an empty but non-NULL encoding are not correctly cloned and trigger a double-free once the duplicates are destroyed.

Medienbericht Exploit
  • EPSS 1.01%
  • Veröffentlicht 23.03.2026 18:33:10
  • Zuletzt bearbeitet 14.07.2026 16:16:53

strongSwan versions 4.5.0 prior to 6.0.5 contain an integer underflow vulnerability in the EAP-TTLS AVP parser that allows unauthenticated remote attackers to cause a denial of service by sending crafted AVP data with invalid length fields during IKE...

  • EPSS 0.91%
  • Veröffentlicht 16.01.2026 00:00:00
  • Zuletzt bearbeitet 15.04.2026 00:35:42

In the eap-mschapv2 plugin (client-side) in strongSwan before 6.0.3, a malicious EAP-MSCHAPv2 server can send a crafted message of size 6 through 8, and cause an integer underflow that potentially results in a heap-based buffer overflow.

  • EPSS 0.47%
  • Veröffentlicht 14.05.2024 11:57:00
  • Zuletzt bearbeitet 06.11.2025 22:25:21

strongSwan versions 5.9.2 through 5.9.5 are affected by authorization bypass through improper validation of certificate with host mismatch (CWE-297). When certificates are used to authenticate clients in TLS-based EAP methods, the IKE or EAP identity...

  • EPSS 2.31%
  • Veröffentlicht 07.12.2023 05:15:09
  • Zuletzt bearbeitet 18.12.2025 16:15:49

strongSwan before 5.9.12 has a buffer overflow and possible unauthenticated remote code execution via a DH public value that exceeds the internal buffer in charon-tkm's DH proxy. The earliest affected version is 5.3.0. An attack can occur via a craft...

  • EPSS 2.28%
  • Veröffentlicht 15.04.2023 00:15:07
  • Zuletzt bearbeitet 07.02.2025 22:15:12

strongSwan 5.9.8 and 5.9.9 potentially allows remote code execution because it uses a variable named "public" for two different purposes within the same function. There is initially incorrect access control, later followed by an expired pointer deref...

  • EPSS 1.68%
  • Veröffentlicht 31.10.2022 06:15:09
  • Zuletzt bearbeitet 06.05.2025 19:15:56

strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a crafted end-entity (and intermediate CA) certificate that contains a CRL/OCSP URL that points to a server (under the attacker's control...

  • EPSS 2.78%
  • Veröffentlicht 31.01.2022 08:15:07
  • Zuletzt bearbeitet 21.11.2024 06:31:54

In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticating the client and (in the case of EAP methods with mutual authentication and EAP-only authentication for IKEv2) even without serv...

  • EPSS 5.2%
  • Veröffentlicht 18.10.2021 14:15:10
  • Zuletzt bearbeitet 21.11.2024 06:27:02

The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to fill the cache and later trigger the replacement of cache entries. The code attempts to select a less...