Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown

CVE-2015-8023

Disclosure Date: November 18, 2015 (last updated October 05, 2023)
The server implementation of the EAP-MSCHAPv2 protocol in the eap-mschapv2 plugin in strongSwan 4.2.12 through 5.x before 5.3.4 does not properly validate local state, which allows remote attackers to bypass authentication via an empty Success message in response to an initial Challenge message.
0
Attacker Value
Unknown

CVE-2015-4171

Disclosure Date: June 10, 2015 (last updated October 05, 2023)
strongSwan 4.3.0 through 5.x before 5.3.2 and strongSwan VPN Client before 1.4.6, when using EAP or pre-shared keys for authenticating an IKEv2 connection, does not enforce server authentication restrictions until the entire authentication process is complete, which allows remote servers to obtain credentials by using a valid certificate and then reading the responses.
0
Attacker Value
Unknown

CVE-2014-9221

Disclosure Date: January 07, 2015 (last updated October 05, 2023)
strongSwan 4.5.x through 5.2.x before 5.2.1 allows remote attackers to cause a denial of service (invalid pointer dereference) via a crafted IKEv2 Key Exchange (KE) message with Diffie-Hellman (DH) group 1025.
0
Attacker Value
Unknown

CVE-2014-2338

Disclosure Date: April 16, 2014 (last updated October 05, 2023)
IKEv2 in strongSwan 4.0.7 before 5.1.3 allows remote attackers to bypass authentication by rekeying an IKE_SA during (1) initiation or (2) re-authentication, which triggers the IKE_SA state to be set to established.
0
Attacker Value
Unknown

CVE-2013-6075

Disclosure Date: November 02, 2013 (last updated October 05, 2023)
The compare_dn function in utils/identification.c in strongSwan 4.3.3 through 5.1.1 allows (1) remote attackers to cause a denial of service (out-of-bounds read, NULL pointer dereference, and daemon crash) or (2) remote authenticated users to impersonate arbitrary users and bypass access restrictions via a crafted ID_DER_ASN1_DN ID, related to an "insufficient length check" during identity comparison.
0
Attacker Value
Unknown

CVE-2013-2944

Disclosure Date: May 02, 2013 (last updated October 05, 2023)
strongSwan 4.3.5 through 5.0.3, when using the OpenSSL plugin for ECDSA signature verification, allows remote attackers to authenticate as other users via an invalid signature.
0
Attacker Value
Unknown

CVE-2012-2388

Disclosure Date: June 27, 2012 (last updated October 04, 2023)
The GMP Plugin in strongSwan 4.2.0 through 4.6.3 allows remote attackers to bypass authentication via a (1) empty or (2) zeroed RSA signature, aka "RSA signature verification vulnerability."
0