The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example, this can be triggered by an unrelated self-signed CA certificate sent by an initiator. Remote code execution cannot occur.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade strongswan | Mar 26, 2024 | Oct 18, 2021 |
| Debian | — | Upgrade strongswan | Nov 29, 2021 | Oct 18, 2021 |
| Dell Powerstore Dsa2023173 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | Jun 21, 2023 |
| Freebsd | — | Upgrade strongswan | Nov 4, 2022 | Jan 25, 2022 |
| Suse | — | Upgrade strongswan-nmUpgrade strongswanUpgrade strongswan-docUpgrade strongswan-sqliteUpgrade strongswan-hmacUpgrade strongswan-libs0Upgrade strongswan-mysqlUpgrade strongswan-ipsec | Oct 20, 2021 | Oct 18, 2021 |
| Ubuntu | — | Upgrade strongswanUpgrade libstrongswan | Oct 20, 2021 | Oct 18, 2021 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Oct 18, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub