The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example, this can be triggered by an unrelated self-signed CA certificate sent by an initiator. Remote code execution cannot occur.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade strongswan | Mar 26, 2024 | Oct 18, 2021 |
| Debian | — | Upgrade strongswan | Nov 29, 2021 | Oct 18, 2021 |
| Dell Powerstore Dsa2023173 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | Jun 21, 2023 |
| Freebsd | — | Upgrade strongswan | Nov 4, 2022 | Jan 25, 2022 |
| Suse | — | Upgrade strongswanUpgrade strongswan-docUpgrade strongswan-nmUpgrade strongswan-mysqlUpgrade strongswan-sqliteUpgrade strongswan-libs0Upgrade strongswan-ipsecUpgrade strongswan-hmac | Oct 20, 2021 | Oct 18, 2021 |
| Ubuntu | — | Upgrade libstrongswanUpgrade strongswan | Oct 20, 2021 | Oct 18, 2021 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Oct 18, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub