CVE-2022-4967
published 2024-05-14CVE-2022-4967: strongSwan versions 5.9.2 through 5.9.5 are affected by authorization bypass through improper validation of certificate with host mismatch (CWE-297). When…
PriorityP340medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.46%
37.1th percentile
strongSwan versions 5.9.2 through 5.9.5 are affected by authorization bypass through improper validation of certificate with host mismatch (CWE-297). When certificates are used to authenticate clients in TLS-based EAP methods, the IKE or EAP identity supplied by a client is not enforced to be contained in the client's certificate. So clients can authenticate with any trusted certificate and claim an arbitrary IKE/EAP identity as their own. This is problematic if the identity is used to make policy decisions. A fix was released in strongSwan version 5.9.6 in August 2022 (e4b4aabc4996fc61c37deab7858d07bc4d220136).
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | strongswan | < strongswan 5.9.6-1 (bookworm) | strongswan 5.9.6-1 (bookworm) |
| strongswan | strongswan | >= 0 < 5.9.6-1 | 5.9.6-1 |
| strongswan | strongswan | >= 0 < 5.9.6-1 | 5.9.6-1 |
| strongswan | strongswan | >= 0 < 5.9.6-1 | 5.9.6-1 |
| strongswan | strongswan | >= 5.9.2 < 5.9.6 | 5.9.6 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
osv6.5MEDIUM
vendor_debian7.7HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2hrc-c28p-9f59: strongSwan versions 5
ghsa_unreviewed·2024-05-14
CVE-2022-4967 [HIGH] GHSA-2hrc-c28p-9f59: strongSwan versions 5
strongSwan versions 5.9.2 through 5.9.5 are affected by authorization bypass through improper validation of certificate with host mismatch (CWE-297). When certificates are used to authenticate clients in TLS-based EAP methods, the IKE or EAP identity supplied by a client is not enforced to be contained in the client's certificate. So clients can authenticate with any trusted certificate and claim an arbitrary IKE/EAP identity as their own. This is problematic if the identity is used to make policy decisions. A fix was released in strongSwan version 5.9.6 in August 2022 (e4b4aabc4996fc61c37deab7858d07bc4d220136).
OSV
CVE-2022-4967: strongSwan versions 5
osv·2024-05-14·CVSS 6.5
CVE-2022-4967 [MEDIUM] CVE-2022-4967: strongSwan versions 5
strongSwan versions 5.9.2 through 5.9.5 are affected by authorization bypass through improper validation of certificate with host mismatch (CWE-297). When certificates are used to authenticate clients in TLS-based EAP methods, the IKE or EAP identity supplied by a client is not enforced to be contained in the client's certificate. So clients can authenticate with any trusted certificate and claim an arbitrary IKE/EAP identity as their own. This is problematic if the identity is used to make policy decisions. A fix was released in strongSwan version 5.9.6 in August 2022 (e4b4aabc4996fc61c37deab7858d07bc4d220136).
Ubuntu
strongSwan vulnerability
vendor_ubuntu·2024-05-14
CVE-2022-4967 strongSwan vulnerability
Title: strongSwan vulnerability
Summary: A valid certificate could be used to impersonate any other user or system
under certain setups.
Jan Schermer discovered that strongSwan incorrectly validated client
certificates in certain configurations. A remote attacker could possibly
use this issue to bypass access controls.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2022-4967: strongswan - strongSwan versions 5.9.2 through 5.9.5 are affected by authorization bypass thr...
vendor_debian·2022·CVSS 7.7
CVE-2022-4967 [HIGH] CVE-2022-4967: strongswan - strongSwan versions 5.9.2 through 5.9.5 are affected by authorization bypass thr...
strongSwan versions 5.9.2 through 5.9.5 are affected by authorization bypass through improper validation of certificate with host mismatch (CWE-297). When certificates are used to authenticate clients in TLS-based EAP methods, the IKE or EAP identity supplied by a client is not enforced to be contained in the client's certificate. So clients can authenticate with any trusted certificate and claim an arbitrary IKE/EAP identity as their own. This is problematic if the identity is used to make policy decisions. A fix was released in strongSwan version 5.9.6 in August 2022 (e4b4aabc4996fc61c37deab7858d07bc4d220136).
Scope: local
bookworm: resolved (fixed in 5.9.6-1)
bullseye: resolved
forky: resolved (fixed in 5.9.6-1)
sid: resolved (fixed in 5.9.6-1)
trixie: resolved (fixed in 5.9.6-1)
No detection rules found.
No public exploits indexed.
Wiz
CVE-2025-62291 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.7
CVE-2025-62291 [HIGH] CVE-2025-62291 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-62291 :
strongSwan vulnerability analysis and mitigation
In the eap-mschapv2 plugin (client-side) in strongSwan before 6.0.3, a malicious EAP-MSCHAPv2 server can send a crafted message of size 6 through 8, and cause an integer underflow that potentially results in a heap-based buffer overflow.
Source : NVD
## 8.1
Score
Published January 16, 2026
Severity HIGH
CNA Score 8.1
Affected Technologies
strongSwan
Linux Fedora
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
strongswan-debugsource
strongswan-libipsec
Sources
NVD
Alpine 3.20, 3.21, 3.22 Severity HIGH Has Fix Added at: Nov 09, 2025
Alpine
Wiz
CVE-2025-9615 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.7
CVE-2025-9615 [HIGH] CVE-2025-9615 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-9615 :
strongSwan vulnerability analysis and mitigation
A flaw was found in NetworkManager. The NetworkManager package allows access to files that may belong to other users. NetworkManager allows non-root users to configure the system's network. The daemon runs with root privileges and can access files owned by users different from the one who added the connection.
Source : NVD
## 3.3
Score
Published January 26, 2026
Severity LOW
CNA Score 3.3
Affected Technologies
strongSwan
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
NetworkManager-config-connectivity-fedora
NetworkManager
Sourc
Wiz
CVE-2026-25075 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.7
CVE-2026-25075 [HIGH] CVE-2026-25075 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-25075 :
strongSwan vulnerability analysis and mitigation
strongSwan versions 4.5.0 prior to 6.0.5 contain an integer underflow vulnerability in the EAP-TTLS AVP parser that allows unauthenticated remote attackers to cause a denial of service by sending crafted AVP data with invalid length fields during IKEv2 authentication. Attackers can exploit the failure to validate AVP length fields before subtraction to trigger excessive memory allocation or NULL pointer dereference, crashing the charon IKE daemon.
Source : NVD
## 8.7
Score
Published March 23, 2026
Severity HIGH
CNA Score 8.7
Affected Technologies
strongSwan
Linux openSUSE
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EP
Bugzilla
CVE-2022-4967 strongswan: potential authorization bypass with TLS-based EAP methods
bugzilla·2024-05-14·CVSS 6.5
CVE-2022-4967 [MEDIUM] CVE-2022-4967 strongswan: potential authorization bypass with TLS-based EAP methods
CVE-2022-4967 strongswan: potential authorization bypass with TLS-based EAP methods
strongSwan versions 5.9.2 through 5.9.5 are affected by authorization bypass through improper validation of certificate with host mismatch (CWE-297). When certificates are used to authenticate clients in TLS-based EAP methods, the IKE or EAP identity supplied by a client is not enforced to be contained in the client's certificate. So clients can authenticate with any trusted certificate and claim an arbitrary IKE/EAP identity as their own. This is problematic if the identity is used to make policy decisions. A fix was released in strongSwan version 5.9.6 in August 2022 (e4b4aabc4996fc61c37deab7858d07bc4d220136).
https://github.com/strongswan/strongswan/commit/e4b4aabc4996fc61c37deab7858d07bc4d220136
https
https://github.com/strongswan/strongswan/commit/e4b4aabc4996fc61c37deab7858d07bc4d220136https://security.netapp.com/advisory/ntap-20240614-0006/https://www.cve.org/CVERecord?id=CVE-2022-4967https://www.strongswan.org/blog/2024/05/13/strongswan-vulnerability-(cve-2022-4967).htmlhttps://github.com/strongswan/strongswan/commit/e4b4aabc4996fc61c37deab7858d07bc4d220136https://security.netapp.com/advisory/ntap-20240614-0006/https://www.cve.org/CVERecord?id=CVE-2022-4967https://www.strongswan.org/blog/2024/05/13/strongswan-vulnerability-(cve-2022-4967).html
2024-05-14
Published