strongSwan 4.3.0 through 5.x before 5.3.2 and strongSwan VPN Client before 1.4.6, when using EAP or pre-shared keys for authenticating an IKEv2 connection, does not enforce server authentication restrictions until the entire authentication process is complete, which allows remote servers to obtain credentials by using a valid certificate and then reading the responses.
CVSS Details
- CVSS 3.1 Base Score: 3.7
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade strongswan | Jul 30, 2024 | Jun 10, 2015 |
| Freebsd | — | Upgrade strongswan | Dec 10, 2025 | Jun 9, 2015 |
| Huawei Euleros 2_0_sp2 | — | Upgrade strongimcv | Feb 22, 2021 | Jun 10, 2015 |
| Suse | — | Upgrade strongswanUpgrade strongswan-ipsecUpgrade strongswan-docUpgrade strongswan-libs0Upgrade strongswan-nmUpgrade strongswan-hmac | Dec 18, 2015 | Jun 10, 2015 |
| Ubuntu | — | Upgrade strongswan-ike | Nov 8, 2024 | Jun 10, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub