In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticating the client and (in the case of EAP methods with mutual authentication and EAP-only authentication for IKEv2) even without server authentication.
CVSS Details
- CVSS 3.1 Base Score: 9.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade strongswan | Mar 26, 2024 | Jan 31, 2022 |
| Debian | — | Upgrade strongswan | Jan 26, 2022 | Jan 26, 2022 |
| Dell Powerstore Dsa2023173 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | Jun 21, 2023 |
| Freebsd | — | Upgrade strongswan | Nov 4, 2022 | Jan 25, 2022 |
| Gentoo Linux | — | Upgrade net-vpn/strongswan. | May 6, 2024 | Jan 31, 2022 |
| Suse | — | Upgrade strongswanUpgrade strongswan-nmUpgrade strongswan-hmacUpgrade strongswan-ipsecUpgrade strongswan-libs0Upgrade strongswan-mysqlUpgrade strongswan-sqliteUpgrade strongswan-doc | Jan 27, 2022 | Jan 24, 2022 |
| Ubuntu | — | Upgrade libstrongswan (Ubuntu Pro)Upgrade libstrongswanUpgrade strongswan (Ubuntu Pro)Upgrade strongswan | Jan 25, 2022 | Jan 24, 2022 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jan 31, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub