vulnerability

FreeBSD: VID-3F9B6943-BA58-11ED-BBBD-00E0670F2660 (CVE-2023-26463): strongSwan -- certificate verification vulnerability

Severity
10
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
Published
Mar 2, 2023
Added
Mar 5, 2023
Modified
Jan 28, 2025

Description

Details for this vulnerability have not been published by NIST at this point. Descriptions from software vendor advisories for this issue are provided below.


From VID-3F9B6943-BA58-11ED-BBBD-00E0670F2660:




strongSwan reports:



A vulnerability related to certificate verification in TLS-based EAP methods


was discovered in strongSwan that results in a denial of service


but possibly even remote code execution. Versions 5.9.8 and 5.9.9


may be affected.




Solution

freebsd-upgrade-package-strongswan
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.