cbcvebase.

Debian Strongswan vulnerabilities

37 known vulnerabilities affecting debian/strongswan.

Total CVEs
37
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH14MEDIUM17LOW2

Vulnerabilities

Page 1 of 2
CVE-2023-41913P2CRITICALCVSS 9.8fixed in strongswan 5.9.8-5+deb12u1 (bookworm)2023
CVE-2023-41913 [CRITICAL] CVE-2023-41913: strongswan - strongSwan before 5.9.12 has a buffer overflow and possible unauthenticated remo... strongSwan before 5.9.12 has a buffer overflow and possible unauthenticated remote code execution via a DH public value that exceeds the internal buffer in charon-tkm's DH proxy. The earliest affected version is 5.3.0. An attack can occur via a crafted IKE_SA_INIT message. Scope: local bookworm: resolved (fixed in 5.9.8-5+deb12u1) bullseye: resolved (fixed in
debian
CVE-2021-45079P2CRITICALCVSS 9.1fixed in strongswan 5.9.5-1 (bookworm)2021
CVE-2021-45079 [CRITICAL] CVE-2021-45079: strongswan - In strongSwan before 5.9.5, a malicious responder can send an EAP-Success messag... In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticating the client and (in the case of EAP methods with mutual authentication and EAP-only authentication for IKEv2) even without server authentication. Scope: local bookworm: resolved (fixed in 5.9.5-1) bullseye: resolved (fixed in 5.9.1-1+deb1
debian
CVE-2023-26463P2CRITICALCVSS 9.8fixed in strongswan 5.9.8-4 (bookworm)2023
CVE-2023-26463 [CRITICAL] CVE-2023-26463: strongswan - strongSwan 5.9.8 and 5.9.9 potentially allows remote code execution because it u... strongSwan 5.9.8 and 5.9.9 potentially allows remote code execution because it uses a variable named "public" for two different purposes within the same function. There is initially incorrect access control, later followed by an expired pointer dereference. One attack vector is sending an untrusted client certificate during EAP-TLS. A server is affected only
debian
CVE-2015-3991P3CRITICALCVSS 9.8fixed in strongswan 5.3.0-2 (bookworm)2015
CVE-2015-3991 [CRITICAL] CVE-2015-3991: strongswan - strongSwan 5.2.2 and 5.3.0 allows remote attackers to cause a denial of service ... strongSwan 5.2.2 and 5.3.0 allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code. Scope: local bookworm: resolved (fixed in 5.3.0-2) bullseye: resolved (fixed in 5.3.0-2) forky: resolved (fixed in 5.3.0-2) sid: resolved (fixed in 5.3.0-2) trixie: resolved (fixed in 5.3.0-2)
debian
CVE-2025-62291P3HIGHCVSS 8.1fixed in strongswan 5.9.8-5+deb12u2 (bookworm)2025
CVE-2025-62291 [HIGH] CVE-2025-62291: strongswan - In the eap-mschapv2 plugin (client-side) in strongSwan before 6.0.3, a malicious... In the eap-mschapv2 plugin (client-side) in strongSwan before 6.0.3, a malicious EAP-MSCHAPv2 server can send a crafted message of size 6 through 8, and cause an integer underflow that potentially results in a heap-based buffer overflow. Scope: local bookworm: resolved (fixed in 5.9.8-5+deb12u2) bullseye: resolved (fixed in 5.9.1-1+deb11u5) forky: resolved (fixed
debian
CVE-2012-2388P3HIGHCVSS 7.5fixed in strongswan 4.5.2-1.4 (bookworm)2012
CVE-2012-2388 [HIGH] CVE-2012-2388: strongswan - The GMP Plugin in strongSwan 4.2.0 through 4.6.3 allows remote attackers to bypa... The GMP Plugin in strongSwan 4.2.0 through 4.6.3 allows remote attackers to bypass authentication via a (1) empty or (2) zeroed RSA signature, aka "RSA signature verification vulnerability." Scope: local bookworm: resolved (fixed in 4.5.2-1.4) bullseye: resolved (fixed in 4.5.2-1.4) forky: resolved (fixed in 4.5.2-1.4) sid: resolved (fixed in 4.5.2-1.4) trixie: res
debian
CVE-2026-25075P3HIGHCVSS 8.7fixed in strongswan 5.9.8-5+deb12u3 (bookworm)2026
CVE-2026-25075 [HIGH] CVE-2026-25075: strongswan - strongSwan versions 4.5.0 prior to 6.0.5 contain an integer underflow vulnerabil... strongSwan versions 4.5.0 prior to 6.0.5 contain an integer underflow vulnerability in the EAP-TTLS AVP parser that allows unauthenticated remote attackers to cause a denial of service by sending crafted AVP data with invalid length fields during IKEv2 authentication. Attackers can exploit the failure to validate AVP length fields before subtraction to trigger ex
debian
CVE-2021-41990P3HIGHCVSS 7.5fixed in strongswan 5.9.4-1 (bookworm)2021
CVE-2021-41990 [HIGH] CVE-2021-41990: strongswan - The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a cr... The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example, this can be triggered by an unrelated self-signed CA certificate sent by an initiator. Remote code execution cannot occur. Scope: local bookworm: resolved (fixed in 5.9.4-1) bullseye: resolved (fixed in 5.9.1-1+deb11u1) fork
debian
CVE-2010-2628P3HIGHCVSS 7.5fixed in strongswan 4.4.1-1 (bookworm)2010
CVE-2010-2628 [HIGH] CVE-2010-2628: strongswan - The IKE daemon in strongSwan 4.3.x before 4.3.7 and 4.4.x before 4.4.1 does not ... The IKE daemon in strongSwan 4.3.x before 4.3.7 and 4.4.x before 4.4.1 does not properly check the return values of snprintf calls, which allows remote attackers to execute arbitrary code via crafted (1) certificate or (2) identity data that triggers buffer overflows. Scope: local bookworm: resolved (fixed in 4.4.1-1) bullseye: resolved (fixed in 4.4.1-1) forky: re
debian
CVE-2018-16151P3HIGHCVSS 7.5fixed in strongswan 5.7.0-1 (bookworm)2018
CVE-2018-16151 [HIGH] CVE-2018-16151: strongswan - In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in st... In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and 5.x before 5.7.0, the RSA implementation based on GMP does not reject excess data after the encoded algorithm OID during PKCS#1 v1.5 signature verification. Similar to the flaw in the same version of strongSwan regarding digestAlgorithm.parameters, a remote attacker c
debian
CVE-2014-2338P3MEDIUMCVSS 6.4fixed in strongswan 5.1.2-4 (bookworm)2014
CVE-2014-2338 [MEDIUM] CVE-2014-2338: strongswan - IKEv2 in strongSwan 4.0.7 before 5.1.3 allows remote attackers to bypass authent... IKEv2 in strongSwan 4.0.7 before 5.1.3 allows remote attackers to bypass authentication by rekeying an IKE_SA during (1) initiation or (2) re-authentication, which triggers the IKE_SA state to be set to established. Scope: local bookworm: resolved (fixed in 5.1.2-4) bullseye: resolved (fixed in 5.1.2-4) forky: resolved (fixed in 5.1.2-4) sid: resolved (fixed in 5
debian
CVE-2021-41991P3HIGHCVSS 7.5fixed in strongswan 5.9.4-1 (bookworm)2021
CVE-2021-41991 [HIGH] CVE-2021-41991: strongswan - The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer ... The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to fill the cache and later trigger the replacement of cache entries. The code attempts to select a less-often-used cache entry by means of a random number generator, but this is not done correctly. Remote code executio
debian
CVE-2018-17540P3HIGHCVSS 7.5fixed in strongswan 5.7.1-1 (bookworm)2018
CVE-2018-17540 [HIGH] CVE-2018-17540: strongswan - The gmp plugin in strongSwan before 5.7.1 has a Buffer Overflow via a crafted ce... The gmp plugin in strongSwan before 5.7.1 has a Buffer Overflow via a crafted certificate. Scope: local bookworm: resolved (fixed in 5.7.1-1) bullseye: resolved (fixed in 5.7.1-1) forky: resolved (fixed in 5.7.1-1) sid: resolved (fixed in 5.7.1-1) trixie: resolved (fixed in 5.7.1-1)
debian
CVE-2018-16152P3MEDIUMCVSS 5.0fixed in strongswan 5.7.0-1 (bookworm)2018
CVE-2018-16152 [MEDIUM] CVE-2018-16152: strongswan - In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in st... In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and 5.x before 5.7.0, the RSA implementation based on GMP does not reject excess data in the digestAlgorithm.parameters field during PKCS#1 v1.5 signature verification. Consequently, a remote attacker can forge signatures when small public exponents are being used, whic
debian
CVE-2022-4967P3HIGHCVSS 7.7fixed in strongswan 5.9.6-1 (bookworm)2022
CVE-2022-4967 [HIGH] CVE-2022-4967: strongswan - strongSwan versions 5.9.2 through 5.9.5 are affected by authorization bypass thr... strongSwan versions 5.9.2 through 5.9.5 are affected by authorization bypass through improper validation of certificate with host mismatch (CWE-297). When certificates are used to authenticate clients in TLS-based EAP methods, the IKE or EAP identity supplied by a client is not enforced to be contained in the client's certificate. So clients can authenticate with a
debian
CVE-2022-40617P3HIGHCVSS 7.5fixed in strongswan 5.9.8-1 (bookworm)2022
CVE-2022-40617 [HIGH] CVE-2022-40617: strongswan - strongSwan before 5.9.8 allows remote attackers to cause a denial of service in ... strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a crafted end-entity (and intermediate CA) certificate that contains a CRL/OCSP URL that points to a server (under the attacker's control) that doesn't properly respond but (for example) just does nothing after the initial TCP handshake, or sends an ex
debian
CVE-2018-10811P3HIGHCVSS 7.5fixed in strongswan 5.6.3-1 (bookworm)2018
CVE-2018-10811 [HIGH] CVE-2018-10811: strongswan - strongSwan 5.6.0 and older allows Remote Denial of Service because of Missing In... strongSwan 5.6.0 and older allows Remote Denial of Service because of Missing Initialization of a Variable. Scope: local bookworm: resolved (fixed in 5.6.3-1) bullseye: resolved (fixed in 5.6.3-1) forky: resolved (fixed in 5.6.3-1) sid: resolved (fixed in 5.6.3-1) trixie: resolved (fixed in 5.6.3-1)
debian
CVE-2017-9022P3HIGHCVSS 7.5fixed in strongswan 5.5.1-4 (bookworm)2017
CVE-2017-9022 [HIGH] CVE-2017-9022: strongswan - The gmp plugin in strongSwan before 5.5.3 does not properly validate RSA public ... The gmp plugin in strongSwan before 5.5.3 does not properly validate RSA public keys before calling mpz_powm_sec, which allows remote peers to cause a denial of service (floating point exception and process crash) via a crafted certificate. Scope: local bookworm: resolved (fixed in 5.5.1-4) bullseye: resolved (fixed in 5.5.1-4) forky: resolved (fixed in 5.5.1-4) si
debian
CVE-2017-11185P3HIGHCVSS 7.5fixed in strongswan 5.6.0-1 (bookworm)2017
CVE-2017-11185 [HIGH] CVE-2017-11185: strongswan - The gmp plugin in strongSwan before 5.6.0 allows remote attackers to cause a den... The gmp plugin in strongSwan before 5.6.0 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted RSA signature. Scope: local bookworm: resolved (fixed in 5.6.0-1) bullseye: resolved (fixed in 5.6.0-1) forky: resolved (fixed in 5.6.0-1) sid: resolved (fixed in 5.6.0-1) trixie: resolved (fixed in 5.6.0-1)
debian
CVE-2017-9023P4HIGHCVSS 7.5fixed in strongswan 5.5.1-4 (bookworm)2017
CVE-2017-9023 [HIGH] CVE-2017-9023: strongswan - The ASN.1 parser in strongSwan before 5.5.3 improperly handles CHOICE types when... The ASN.1 parser in strongSwan before 5.5.3 improperly handles CHOICE types when the x509 plugin is enabled, which allows remote attackers to cause a denial of service (infinite loop) via a crafted certificate. Scope: local bookworm: resolved (fixed in 5.5.1-4) bullseye: resolved (fixed in 5.5.1-4) forky: resolved (fixed in 5.5.1-4) sid: resolved (fixed in 5.5.1-4)
debian