Strongswan
by Strongswan
Source repositories
CVEs (52)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-16152 | Hig | 0.42 | 7.5 | 0.02 | Sep 26, 2018 | In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and 5.x before 5.7.0, the RSA implementation based on GMP does not reject excess data in the digestAlgorithm.parameters field during PKCS#1 v1.5 signature verification. Consequently, a… | ||
| CVE-2026-78134 | Hig | 0.39 | 7.1 | 0.00 | Sep 11, 2026 | strongSwan 4.5.0 through 6.0.7 has Incorrect Access Control in the eap-ttls and eap-peap plugins because there can be a missing or mismatched inner EAP identity. | ||
| CVE-2018-5389 | Med | 0.39 | 5.9 | 0.03 | Sep 6, 2018 | The Internet Key Exchange v1 main mode is vulnerable to offline dictionary or brute force attacks. Reusing a key pair across different versions and modes of IKE could lead to cross-protocol authentication bypasses. It is well known, that the aggressive mode of IKEv1 PSK is… | ||
| CVE-2018-6459 | Med | 0.35 | 5.3 | 0.01 | Feb 20, 2018 | The rsa_pss_params_parse function in libstrongswan/credentials/keys/signature_params.c in strongSwan 5.6.1 allows remote attackers to cause a denial of service via a crafted RSASSA-PSS signature that lacks a mask generation function parameter. | ||
| CVE-2026-78129 | Med | 0.31 | 5.9 | 0.00 | Sep 11, 2026 | strongSwan 4.6.2 through 6.0.7 has an infinite loop in PKCS#5 decryption. | ||
| CVE-2026-78126 | Med | 0.31 | 5.9 | 0.00 | Sep 11, 2026 | strongSwan 4.1.10 through 6.0.7 allows a NULL pointer dereference in the eap-aka plugin. | ||
| CVE-2026-78123 | Med | 0.31 | 5.9 | 0.00 | Sep 11, 2026 | strongSwan 5.0.2 through 6.0.7 has an Expired Pointer Dereference in PKCS#7 parsing in the openssl plugin. | ||
| CVE-2026-78135 | Med | 0.29 | 5.6 | 0.00 | Sep 11, 2026 | libcharon in strongSwan 5.9.7 through 6.0.7 mishandles behavioral workflow in the IKEv2 state machine. Because CREATE_CHILD_SA requests are mishandled, there can be an authentication bypass. | ||
| CVE-2019-10155 | Low | 0.20 | 3.1 | 0.01 | Jun 12, 2019 | The Libreswan Project has found a vulnerability in the processing of IKEv1 informational exchange packets which are encrypted and integrity protected using the established IKE SA encryption and integrity keys, but as a receiver, the integrity check value was not verified. This… | ||
| CVE-2026-78131 | Low | 0.17 | 3.7 | 0.00 | Sep 11, 2026 | strongSwan 4.2.0 through 6.0.7 has a missing release of memory after its effective lifetime in the x509 plugin's attribute certificate parser. | ||
| CVE-2026-78127 | Low | 0.17 | 3.7 | 0.00 | Sep 11, 2026 | libcharon in strongSwan 4.1.2 through 6.0.7 has a missing release of memory after its effective lifetime in the IKE message parser. | ||
| CVE-2026-78124 | Low | 0.17 | 3.7 | 0.00 | Sep 11, 2026 | strongSwan 5.0.2 through 6.0.7 allows PKCS#7 certificate enumeration in the openssl plugin that leads to a lack of release of memory after its effective lifetime. | ||
| CVE-2022-4967 | Hig | 0.00 | 7.7 | 0.00 | May 14, 2024 | strongSwan versions 5.9.2 through 5.9.5 are affected by authorization bypass through improper validation of certificate with host mismatch (CWE-297). When certificates are used to authenticate clients in TLS-based EAP methods, the IKE or EAP identity supplied by a client is not… | ||
| CVE-2015-8023 | 0.00 | — | 0.03 | Nov 18, 2015 | The server implementation of the EAP-MSCHAPv2 protocol in the eap-mschapv2 plugin in strongSwan 4.2.12 through 5.x before 5.3.4 does not properly validate local state, which allows remote attackers to bypass authentication via an empty Success message in response to an initial… | |||
| CVE-2015-4171 | 0.00 | — | 0.02 | Jun 10, 2015 | strongSwan 4.3.0 through 5.x before 5.3.2 and strongSwan VPN Client before 1.4.6, when using EAP or pre-shared keys for authenticating an IKEv2 connection, does not enforce server authentication restrictions until the entire authentication process is complete, which allows… | |||
| CVE-2014-9221 | 0.00 | — | 0.04 | Jan 7, 2015 | strongSwan 4.5.x through 5.2.x before 5.2.1 allows remote attackers to cause a denial of service (invalid pointer dereference) via a crafted IKEv2 Key Exchange (KE) message with Diffie-Hellman (DH) group 1025. | |||
| CVE-2014-2891 | 0.00 | — | 0.03 | May 7, 2014 | strongSwan before 5.1.2 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon crash) via a crafted ID_DER_ASN1_DN ID payload. | |||
| CVE-2014-2338 | 0.00 | — | 0.02 | Apr 16, 2014 | IKEv2 in strongSwan 4.0.7 before 5.1.3 allows remote attackers to bypass authentication by rekeying an IKE_SA during (1) initiation or (2) re-authentication, which triggers the IKE_SA state to be set to established. | |||
| CVE-2013-6076 | 0.00 | — | 0.02 | Nov 2, 2013 | strongSwan 5.0.2 through 5.1.0 allows remote attackers to cause a denial of service (NULL pointer dereference and charon daemon crash) via a crafted IKEv1 fragmentation packet. | |||
| CVE-2013-6075 | 0.00 | — | 0.02 | Nov 2, 2013 | The compare_dn function in utils/identification.c in strongSwan 4.3.3 through 5.1.1 allows (1) remote attackers to cause a denial of service (out-of-bounds read, NULL pointer dereference, and daemon crash) or (2) remote authenticated users to impersonate arbitrary users and… |
- risk 0.42cvss 7.5epss 0.02
In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and 5.x before 5.7.0, the RSA implementation based on GMP does not reject excess data in the digestAlgorithm.parameters field during PKCS#1 v1.5 signature verification. Consequently, a…
- risk 0.39cvss 7.1epss 0.00
strongSwan 4.5.0 through 6.0.7 has Incorrect Access Control in the eap-ttls and eap-peap plugins because there can be a missing or mismatched inner EAP identity.
- risk 0.39cvss 5.9epss 0.03
The Internet Key Exchange v1 main mode is vulnerable to offline dictionary or brute force attacks. Reusing a key pair across different versions and modes of IKE could lead to cross-protocol authentication bypasses. It is well known, that the aggressive mode of IKEv1 PSK is…
- risk 0.35cvss 5.3epss 0.01
The rsa_pss_params_parse function in libstrongswan/credentials/keys/signature_params.c in strongSwan 5.6.1 allows remote attackers to cause a denial of service via a crafted RSASSA-PSS signature that lacks a mask generation function parameter.
- risk 0.31cvss 5.9epss 0.00
strongSwan 4.6.2 through 6.0.7 has an infinite loop in PKCS#5 decryption.
- risk 0.31cvss 5.9epss 0.00
strongSwan 4.1.10 through 6.0.7 allows a NULL pointer dereference in the eap-aka plugin.
- risk 0.31cvss 5.9epss 0.00
strongSwan 5.0.2 through 6.0.7 has an Expired Pointer Dereference in PKCS#7 parsing in the openssl plugin.
- risk 0.29cvss 5.6epss 0.00
libcharon in strongSwan 5.9.7 through 6.0.7 mishandles behavioral workflow in the IKEv2 state machine. Because CREATE_CHILD_SA requests are mishandled, there can be an authentication bypass.
- risk 0.20cvss 3.1epss 0.01
The Libreswan Project has found a vulnerability in the processing of IKEv1 informational exchange packets which are encrypted and integrity protected using the established IKE SA encryption and integrity keys, but as a receiver, the integrity check value was not verified. This…
- risk 0.17cvss 3.7epss 0.00
strongSwan 4.2.0 through 6.0.7 has a missing release of memory after its effective lifetime in the x509 plugin's attribute certificate parser.
- risk 0.17cvss 3.7epss 0.00
libcharon in strongSwan 4.1.2 through 6.0.7 has a missing release of memory after its effective lifetime in the IKE message parser.
- risk 0.17cvss 3.7epss 0.00
strongSwan 5.0.2 through 6.0.7 allows PKCS#7 certificate enumeration in the openssl plugin that leads to a lack of release of memory after its effective lifetime.
- risk 0.00cvss 7.7epss 0.00
strongSwan versions 5.9.2 through 5.9.5 are affected by authorization bypass through improper validation of certificate with host mismatch (CWE-297). When certificates are used to authenticate clients in TLS-based EAP methods, the IKE or EAP identity supplied by a client is not…
- CVE-2015-8023Nov 18, 2015risk 0.00cvss —epss 0.03
The server implementation of the EAP-MSCHAPv2 protocol in the eap-mschapv2 plugin in strongSwan 4.2.12 through 5.x before 5.3.4 does not properly validate local state, which allows remote attackers to bypass authentication via an empty Success message in response to an initial…
- CVE-2015-4171Jun 10, 2015risk 0.00cvss —epss 0.02
strongSwan 4.3.0 through 5.x before 5.3.2 and strongSwan VPN Client before 1.4.6, when using EAP or pre-shared keys for authenticating an IKEv2 connection, does not enforce server authentication restrictions until the entire authentication process is complete, which allows…
- CVE-2014-9221Jan 7, 2015risk 0.00cvss —epss 0.04
strongSwan 4.5.x through 5.2.x before 5.2.1 allows remote attackers to cause a denial of service (invalid pointer dereference) via a crafted IKEv2 Key Exchange (KE) message with Diffie-Hellman (DH) group 1025.
- CVE-2014-2891May 7, 2014risk 0.00cvss —epss 0.03
strongSwan before 5.1.2 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon crash) via a crafted ID_DER_ASN1_DN ID payload.
- CVE-2014-2338Apr 16, 2014risk 0.00cvss —epss 0.02
IKEv2 in strongSwan 4.0.7 before 5.1.3 allows remote attackers to bypass authentication by rekeying an IKE_SA during (1) initiation or (2) re-authentication, which triggers the IKE_SA state to be set to established.
- CVE-2013-6076Nov 2, 2013risk 0.00cvss —epss 0.02
strongSwan 5.0.2 through 5.1.0 allows remote attackers to cause a denial of service (NULL pointer dereference and charon daemon crash) via a crafted IKEv1 fragmentation packet.
- CVE-2013-6075Nov 2, 2013risk 0.00cvss —epss 0.02
The compare_dn function in utils/identification.c in strongSwan 4.3.3 through 5.1.1 allows (1) remote attackers to cause a denial of service (out-of-bounds read, NULL pointer dereference, and daemon crash) or (2) remote authenticated users to impersonate arbitrary users and…
Page 2 of 3