Search

Find a vulnerability

Search criteria

    25 vulnerabilities by StrongSwan

    CERTFR-2026-AVI-1180

    Vulnerability from certfr_avis - Published: 2026-09-16 - Updated: 2026-09-16

    Une vulnérabilité a été découverte dans StrongSwan. Elle permet à un attaquant de provoquer un déni de service à distance.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    StrongSwan strongSwan strongSwan versions antérieures à 6.1.0
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "strongSwan versions ant\u00e9rieures \u00e0 6.1.0",
          "product": {
            "name": "strongSwan",
            "vendor": {
              "name": "StrongSwan",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2026-78123",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-78123"
        }
      ],
      "initial_release_date": "2026-09-16T00:00:00",
      "last_revision_date": "2026-09-16T00:00:00",
      "links": [],
      "reference": "CERTFR-2026-AVI-1180",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2026-09-16T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "D\u00e9ni de service \u00e0 distance"
        }
      ],
      "summary": "Une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 d\u00e9couverte dans StrongSwan. Elle permet \u00e0 un attaquant de provoquer un d\u00e9ni de service \u00e0 distance.",
      "title": "Vuln\u00e9rabilit\u00e9 dans StrongSwan",
      "vendor_advisories": [
        {
          "published_at": "2026-09-07",
          "title": "Bulletin de s\u00e9curit\u00e9 StrongSwan cve-2026-78123",
          "url": "https://www.strongswan.org//blog/2026/09/07/strongswan-vulnerability-(cve-2026-78123).html"
        }
      ]
    }

    CERTFR-2026-AVI-1129

    Vulnerability from certfr_avis - Published: 2026-09-08 - Updated: 2026-09-08

    De multiples vulnérabilités ont été découvertes dans strongSwan. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et un contournement de la politique de sécurité.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    StrongSwan strongSwan strongSwan versions antérieures à 6.1.0
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "strongSwan versions ant\u00e9rieures \u00e0 6.1.0",
          "product": {
            "name": "strongSwan",
            "vendor": {
              "name": "StrongSwan",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2026-78134",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-78134"
        },
        {
          "name": "CVE-2026-78127",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-78127"
        },
        {
          "name": "CVE-2017-9023",
          "url": "https://www.cve.org/CVERecord?id=CVE-2017-9023"
        },
        {
          "name": "CVE-2026-78129",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-78129"
        },
        {
          "name": "CVE-2026-78135",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-78135"
        },
        {
          "name": "CVE-2026-78132",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-78132"
        },
        {
          "name": "CVE-2026-78133",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-78133"
        },
        {
          "name": "CVE-2014-2338",
          "url": "https://www.cve.org/CVERecord?id=CVE-2014-2338"
        },
        {
          "name": "CVE-2026-78131",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-78131"
        },
        {
          "name": "CVE-2026-78130",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-78130"
        }
      ],
      "initial_release_date": "2026-09-08T00:00:00",
      "last_revision_date": "2026-09-08T00:00:00",
      "links": [],
      "reference": "CERTFR-2026-AVI-1129",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2026-09-08T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "D\u00e9ni de service \u00e0 distance"
        },
        {
          "description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
        },
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans strongSwan. Certaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer une ex\u00e9cution de code arbitraire \u00e0 distance, un d\u00e9ni de service \u00e0 distance et un contournement de la politique de s\u00e9curit\u00e9.",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans strongSwan",
      "vendor_advisories": [
        {
          "published_at": "2026-09-07",
          "title": "Bulletin de s\u00e9curit\u00e9 StrongSwan cve-2026-78131",
          "url": "https://www.strongswan.org//blog/2026/09/07/strongswan-vulnerability-(cve-2026-78131).html"
        },
        {
          "published_at": "2026-09-07",
          "title": "Bulletin de s\u00e9curit\u00e9 StrongSwan cve-2026-78129",
          "url": "https://www.strongswan.org//blog/2026/09/07/strongswan-vulnerability-(cve-2026-78129).html"
        },
        {
          "published_at": "2026-09-07",
          "title": "Bulletin de s\u00e9curit\u00e9 StrongSwan cve-2026-78127",
          "url": "https://www.strongswan.org//blog/2026/09/07/strongswan-vulnerability-(cve-2026-78127).html"
        },
        {
          "published_at": "2026-09-07",
          "title": "Bulletin de s\u00e9curit\u00e9 StrongSwan cve-2026-78134",
          "url": "https://www.strongswan.org//blog/2026/09/07/strongswan-vulnerability-(cve-2026-78134).html"
        },
        {
          "published_at": "2026-09-07",
          "title": "Bulletin de s\u00e9curit\u00e9 StrongSwan cve-2026-78135",
          "url": "https://www.strongswan.org//blog/2026/09/07/strongswan-vulnerability-(cve-2026-78135).html"
        },
        {
          "published_at": "2026-09-07",
          "title": "Bulletin de s\u00e9curit\u00e9 StrongSwan cve-2026-78130",
          "url": "https://www.strongswan.org//blog/2026/09/07/strongswan-vulnerability-(cve-2026-78130).html"
        },
        {
          "published_at": "2026-09-07",
          "title": "Bulletin de s\u00e9curit\u00e9 StrongSwan cve-2026-78132",
          "url": "https://www.strongswan.org//blog/2026/09/07/strongswan-vulnerability-(cve-2026-78132).html"
        },
        {
          "published_at": "2026-09-07",
          "title": "Bulletin de s\u00e9curit\u00e9 StrongSwan cve-2026-78133",
          "url": "https://www.strongswan.org//blog/2026/09/07/strongswan-vulnerability-(cve-2026-78133).html"
        }
      ]
    }

    CERTFR-2026-AVI-0709

    Vulnerability from certfr_avis - Published: 2026-06-09 - Updated: 2026-06-09

    Une vulnérabilité a été découverte dans strongSwan. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    StrongSwan strongSwan strongSwan versions antérieures à 6.0.7
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "strongSwan versions ant\u00e9rieures \u00e0 6.0.7",
          "product": {
            "name": "strongSwan",
            "vendor": {
              "name": "StrongSwan",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2026-47895",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-47895"
        }
      ],
      "initial_release_date": "2026-06-09T00:00:00",
      "last_revision_date": "2026-06-09T00:00:00",
      "links": [],
      "reference": "CERTFR-2026-AVI-0709",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2026-06-09T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
        }
      ],
      "summary": "Une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 d\u00e9couverte dans strongSwan. Elle permet \u00e0 un attaquant de provoquer une ex\u00e9cution de code arbitraire \u00e0 distance.",
      "title": "Vuln\u00e9rabilit\u00e9 dans strongSwan",
      "vendor_advisories": [
        {
          "published_at": "2026-06-08",
          "title": "Bulletin de s\u00e9curit\u00e9 StrongSwan cve-2026-47895",
          "url": "https://www.strongswan.org//blog/2026/06/08/strongswan-vulnerability-(cve-2026-47895).html"
        }
      ]
    }

    CERTFR-2026-AVI-0484

    Vulnerability from certfr_avis - Published: 2026-04-23 - Updated: 2026-04-23

    De multiples vulnérabilités ont été découvertes dans strongSwan. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et un contournement de la politique de sécurité.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    StrongSwan strongSwan strongSwan versions antérieures à 6.0.6
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "strongSwan versions ant\u00e9rieures \u00e0 6.0.6",
          "product": {
            "name": "strongSwan",
            "vendor": {
              "name": "StrongSwan",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2026-35330",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-35330"
        },
        {
          "name": "CVE-2026-35332",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-35332"
        },
        {
          "name": "CVE-2026-35333",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-35333"
        },
        {
          "name": "CVE-2026-35328",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-35328"
        },
        {
          "name": "CVE-2026-35331",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-35331"
        },
        {
          "name": "CVE-2026-35334",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-35334"
        },
        {
          "name": "CVE-2026-35329",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-35329"
        }
      ],
      "initial_release_date": "2026-04-23T00:00:00",
      "last_revision_date": "2026-04-23T00:00:00",
      "links": [],
      "reference": "CERTFR-2026-AVI-0484",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2026-04-23T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "D\u00e9ni de service \u00e0 distance"
        },
        {
          "description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
        },
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans strongSwan. Certaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer une ex\u00e9cution de code arbitraire \u00e0 distance, un d\u00e9ni de service \u00e0 distance et un contournement de la politique de s\u00e9curit\u00e9.",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans strongSwan",
      "vendor_advisories": [
        {
          "published_at": "2026-04-22",
          "title": "Bulletin de s\u00e9curit\u00e9 StrongSwan cve-2026-35334",
          "url": "https://www.strongswan.org//blog/2026/04/22/strongswan-vulnerability-(cve-2026-35334).html"
        },
        {
          "published_at": "2026-04-22",
          "title": "Bulletin de s\u00e9curit\u00e9 StrongSwan cve-2026-35329",
          "url": "https://www.strongswan.org//blog/2026/04/22/strongswan-vulnerability-(cve-2026-35329).html"
        },
        {
          "published_at": "2026-04-22",
          "title": "Bulletin de s\u00e9curit\u00e9 StrongSwan cve-2026-35333",
          "url": "https://www.strongswan.org//blog/2026/04/22/strongswan-vulnerability-(cve-2026-35333).html"
        },
        {
          "published_at": "2026-04-22",
          "title": "Bulletin de s\u00e9curit\u00e9 StrongSwan cve-2026-35331",
          "url": "https://www.strongswan.org//blog/2026/04/22/strongswan-vulnerability-(cve-2026-35331).html"
        },
        {
          "published_at": "2026-04-22",
          "title": "Bulletin de s\u00e9curit\u00e9 StrongSwan cve-2026-35330",
          "url": "https://www.strongswan.org//blog/2026/04/22/strongswan-vulnerability-(cve-2026-35330).html"
        },
        {
          "published_at": "2026-04-22",
          "title": "Bulletin de s\u00e9curit\u00e9 StrongSwan cve-2026-35328",
          "url": "https://www.strongswan.org//blog/2026/04/22/strongswan-vulnerability-(cve-2026-35328).html"
        },
        {
          "published_at": "2026-04-22",
          "title": "Bulletin de s\u00e9curit\u00e9 StrongSwan cve-2026-35332",
          "url": "https://www.strongswan.org//blog/2026/04/22/strongswan-vulnerability-(cve-2026-35332).html"
        }
      ]
    }

    CERTFR-2026-AVI-0344

    Vulnerability from certfr_avis - Published: 2026-03-24 - Updated: 2026-03-24

    Une vulnérabilité a été découverte dans strongSwan. Elle permet à un attaquant de provoquer un déni de service à distance.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    StrongSwan strongSwan strongSwan versions antérieures à 6.0.5
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "strongSwan versions ant\u00e9rieures \u00e0 6.0.5",
          "product": {
            "name": "strongSwan",
            "vendor": {
              "name": "StrongSwan",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2026-25075",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-25075"
        }
      ],
      "initial_release_date": "2026-03-24T00:00:00",
      "last_revision_date": "2026-03-24T00:00:00",
      "links": [],
      "reference": "CERTFR-2026-AVI-0344",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2026-03-24T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "D\u00e9ni de service \u00e0 distance"
        }
      ],
      "summary": "Une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 d\u00e9couverte dans strongSwan. Elle permet \u00e0 un attaquant de provoquer un d\u00e9ni de service \u00e0 distance.",
      "title": "Vuln\u00e9rabilit\u00e9 dans strongSwan",
      "vendor_advisories": [
        {
          "published_at": "2026-03-23",
          "title": "Bulletin de s\u00e9curit\u00e9 StrongSwan cve-2026-25075",
          "url": "https://www.strongswan.org//blog/2026/03/23/strongswan-vulnerability-(cve-2026-25075).html"
        }
      ]
    }

    CERTFR-2025-AVI-1109

    Vulnerability from certfr_avis - Published: 2025-12-15 - Updated: 2025-12-15

    Une vulnérabilité a été découverte dans StrongSwan. Elle permet à un attaquant de provoquer un contournement de la politique de sécurité.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Des correctifs de sécurité sont mis à disposition par l'éditeur pour certaines versions de strongSwan et NetworkManager-strongswan, se référer à l'avis éditeur.

    Impacted products
    Vendor Product Description
    StrongSwan strongSwan strongSwan versions postérieures à 4.x et antérieures à 6.0.4
    StrongSwan strongSwan greffon NetworkManager-strongswan versions antérieures à 1.6.4
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "strongSwan versions post\u00e9rieures \u00e0 4.x et ant\u00e9rieures \u00e0 6.0.4",
          "product": {
            "name": "strongSwan",
            "vendor": {
              "name": "StrongSwan",
              "scada": false
            }
          }
        },
        {
          "description": "greffon NetworkManager-strongswan versions ant\u00e9rieures \u00e0 1.6.4",
          "product": {
            "name": "strongSwan",
            "vendor": {
              "name": "StrongSwan",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "Des correctifs de s\u00e9curit\u00e9 sont mis \u00e0 disposition par l\u0027\u00e9diteur pour certaines versions de strongSwan et  NetworkManager-strongswan, se r\u00e9f\u00e9rer \u00e0 l\u0027avis \u00e9diteur.",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2025-9615",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-9615"
        }
      ],
      "initial_release_date": "2025-12-15T00:00:00",
      "last_revision_date": "2025-12-15T00:00:00",
      "links": [],
      "reference": "CERTFR-2025-AVI-1109",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2025-12-15T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        }
      ],
      "summary": "Une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 d\u00e9couverte dans StrongSwan. Elle permet \u00e0 un attaquant de provoquer un contournement de la politique de s\u00e9curit\u00e9.",
      "title": "Vuln\u00e9rabilit\u00e9 dans strongSwan",
      "vendor_advisories": [
        {
          "published_at": "2025-12-12",
          "title": "Bulletin de s\u00e9curit\u00e9 StrongSwan cve-2025-9615",
          "url": "https://www.strongswan.org//blog/2025/12/12/strongswan-vulnerability-(cve-2025-9615).html"
        }
      ]
    }

    CERTFR-2025-AVI-0931

    Vulnerability from certfr_avis - Published: 2025-10-28 - Updated: 2025-10-28

    Une vulnérabilité a été découverte dans StrongSwan. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance et un déni de service à distance.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    StrongSwan strongSwan strongSwan versions antérieures à 6.0.3 avec le Greffon eap-mschapv2
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "strongSwan versions ant\u00e9rieures \u00e0 6.0.3 avec le Greffon eap-mschapv2",
          "product": {
            "name": "strongSwan",
            "vendor": {
              "name": "StrongSwan",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2025-62291",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-62291"
        }
      ],
      "initial_release_date": "2025-10-28T00:00:00",
      "last_revision_date": "2025-10-28T00:00:00",
      "links": [],
      "reference": "CERTFR-2025-AVI-0931",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2025-10-28T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "D\u00e9ni de service \u00e0 distance"
        },
        {
          "description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
        }
      ],
      "summary": "Une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 d\u00e9couverte dans StrongSwan. Elle permet \u00e0 un attaquant de provoquer une ex\u00e9cution de code arbitraire \u00e0 distance et un d\u00e9ni de service \u00e0 distance.",
      "title": "Vuln\u00e9rabilit\u00e9 dans StrongSwan",
      "vendor_advisories": [
        {
          "published_at": "2025-10-27",
          "title": "Bulletin de s\u00e9curit\u00e9 StrongSwan cve-2025-62291",
          "url": "https://www.strongswan.org//blog/2025/10/27/strongswan-vulnerability-(cve-2025-62291).html"
        }
      ]
    }

    CVE-2026-78135 (GCVE-0-2026-78135)

    Vulnerability from cvelistv5 – Published: 2026-09-11 02:07 – Updated: 2026-09-15 15:32
    VLAI
    Summary
    libcharon in strongSwan 5.9.7 through 6.0.7 mishandles behavioral workflow in the IKEv2 state machine. Because CREATE_CHILD_SA requests are mishandled, there can be an authentication bypass.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-15 15:32 UTC
    CWE
    • CWE-841 - Improper Enforcement of Behavioral Workflow
    Impacted products
    Vendor Product Version
    strongSwan strongSwan Affected: 5.9.7 , < 6.1.0 (semver)
        cpe:2.3:a:strongswan:strongswan:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-78135",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-15T15:32:40.015957Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-15T15:32:51.934Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "strongSwan",
              "vendor": "strongSwan",
              "versions": [
                {
                  "lessThan": "6.1.0",
                  "status": "affected",
                  "version": "5.9.7",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:strongswan:strongswan:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.1.0",
                      "versionStartIncluding": "5.9.7",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "libcharon in strongSwan 5.9.7 through 6.0.7 mishandles behavioral workflow in the IKEv2 state machine. Because\u00a0CREATE_CHILD_SA requests are mishandled, there can be an authentication bypass."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 5.6,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-841",
                  "description": "CWE-841 Improper Enforcement of Behavioral Workflow",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-11T02:07:28.763Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://github.com/strongswan/strongswan/releases/tag/6.1.0"
            },
            {
              "url": "https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78135).html"
            }
          ],
          "x_generator": {
            "engine": "CVE-Request-form 0.0.1"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2026-78135",
        "datePublished": "2026-09-11T02:07:28.763Z",
        "dateReserved": "2026-08-22T23:41:22.635Z",
        "dateUpdated": "2026-09-15T15:32:51.934Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-78134 (GCVE-0-2026-78134)

    Vulnerability from cvelistv5 – Published: 2026-09-11 02:00 – Updated: 2026-09-11 14:14
    VLAI
    Summary
    strongSwan 4.5.0 through 6.0.7 has Incorrect Access Control in the eap-ttls and eap-peap plugins because there can be a missing or mismatched inner EAP identity.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-11 14:13 UTC
    CWE
    • CWE-863 - Incorrect Authorization
    Impacted products
    Vendor Product Version
    strongSwan strongSwan Affected: 4.5.0 , < 6.1.0 (semver)
        cpe:2.3:a:strongswan:strongswan:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-78134",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-11T14:13:41.050447Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-11T14:14:06.979Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "strongSwan",
              "vendor": "strongSwan",
              "versions": [
                {
                  "lessThan": "6.1.0",
                  "status": "affected",
                  "version": "4.5.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:strongswan:strongswan:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.1.0",
                      "versionStartIncluding": "4.5.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "strongSwan 4.5.0 through 6.0.7 has Incorrect Access Control in the eap-ttls and eap-peap plugins because there can be a missing or mismatched inner EAP identity."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-863",
                  "description": "CWE-863 Incorrect Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-11T02:00:46.749Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://github.com/strongswan/strongswan/releases/tag/6.1.0"
            },
            {
              "url": "https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78134).html"
            }
          ],
          "x_generator": {
            "engine": "CVE-Request-form 0.0.1"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2026-78134",
        "datePublished": "2026-09-11T02:00:46.749Z",
        "dateReserved": "2026-08-22T23:39:46.284Z",
        "dateUpdated": "2026-09-11T14:14:06.979Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-78133 (GCVE-0-2026-78133)

    Vulnerability from cvelistv5 – Published: 2026-09-11 01:52 – Updated: 2026-09-11 16:54
    VLAI
    Summary
    libcharon in strongSwan 6.0.0 through 6.0.7 has a use-after-free in IKEv2 rekeying collision handling.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-11 16:53 UTC
    CWE
    Impacted products
    Vendor Product Version
    strongSwan strongSwan Affected: 6.0.0 , < 6.1.0 (semver)
        cpe:2.3:a:strongswan:strongswan:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-78133",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-11T16:53:54.390946Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-11T16:54:19.406Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "strongSwan",
              "vendor": "strongSwan",
              "versions": [
                {
                  "lessThan": "6.1.0",
                  "status": "affected",
                  "version": "6.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:strongswan:strongswan:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.1.0",
                      "versionStartIncluding": "6.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "libcharon in strongSwan 6.0.0 through 6.0.7 has a use-after-free in IKEv2 rekeying collision handling."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-416",
                  "description": "CWE-416 Use After Free",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-11T01:52:30.872Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://github.com/strongswan/strongswan/releases/tag/6.1.0"
            },
            {
              "url": "https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78133).html"
            }
          ],
          "x_generator": {
            "engine": "CVE-Request-form 0.0.1"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2026-78133",
        "datePublished": "2026-09-11T01:52:30.872Z",
        "dateReserved": "2026-08-22T23:37:38.545Z",
        "dateUpdated": "2026-09-11T16:54:19.406Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-78132 (GCVE-0-2026-78132)

    Vulnerability from cvelistv5 – Published: 2026-09-11 01:49 – Updated: 2026-09-14 18:18
    VLAI
    Summary
    strongSwan 5.1.3 through 6.0.7 has an infinite loop in the x509 plugin's attribute certificate parser for ietfAttrSyntax.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-14 15:10 UTC
    CWE
    • CWE-835 - Loop with Unreachable Exit Condition ('Infinite Loop')
    Impacted products
    Vendor Product Version
    strongSwan strongSwan Affected: 5.1.3 , < 6.1.0 (semver)
        cpe:2.3:a:strongswan:strongswan:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-78132",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-14T15:10:36.917536Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-14T18:18:29.968Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "strongSwan",
              "vendor": "strongSwan",
              "versions": [
                {
                  "lessThan": "6.1.0",
                  "status": "affected",
                  "version": "5.1.3",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:strongswan:strongswan:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.1.0",
                      "versionStartIncluding": "5.1.3",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "strongSwan 5.1.3 through 6.0.7 has an infinite loop in the x509 plugin\u0027s attribute certificate parser for\u00a0ietfAttrSyntax."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-835",
                  "description": "CWE-835 Loop with Unreachable Exit Condition (\u0027Infinite Loop\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-11T01:49:15.049Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78132).html"
            },
            {
              "url": "https://github.com/strongswan/strongswan/releases/tag/6.1.0"
            }
          ],
          "x_generator": {
            "engine": "CVE-Request-form 0.0.1"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2026-78132",
        "datePublished": "2026-09-11T01:49:15.049Z",
        "dateReserved": "2026-08-22T23:35:56.619Z",
        "dateUpdated": "2026-09-14T18:18:29.968Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-78131 (GCVE-0-2026-78131)

    Vulnerability from cvelistv5 – Published: 2026-09-11 01:45 – Updated: 2026-09-11 20:04
    VLAI
    Summary
    strongSwan 4.2.0 through 6.0.7 has a missing release of memory after its effective lifetime in the x509 plugin's attribute certificate parser.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-11 20:04 UTC
    CWE
    • CWE-401 - Missing Release of Memory after Effective Lifetime
    Impacted products
    Vendor Product Version
    strongSwan strongSwan Affected: 4.2.0 , < 6.1.0 (semver)
        cpe:2.3:a:strongswan:strongswan:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-78131",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-11T20:04:08.511118Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-11T20:04:15.477Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "strongSwan",
              "vendor": "strongSwan",
              "versions": [
                {
                  "lessThan": "6.1.0",
                  "status": "affected",
                  "version": "4.2.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:strongswan:strongswan:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.1.0",
                      "versionStartIncluding": "4.2.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "strongSwan 4.2.0 through 6.0.7 has a missing release of memory after its effective lifetime in the x509 plugin\u0027s attribute certificate parser."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 3.7,
                "baseSeverity": "LOW",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-401",
                  "description": "CWE-401 Missing Release of Memory after Effective Lifetime",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-11T01:45:58.539Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://github.com/strongswan/strongswan/releases/tag/6.1.0"
            },
            {
              "url": "https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78131).html"
            }
          ],
          "x_generator": {
            "engine": "CVE-Request-form 0.0.1"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2026-78131",
        "datePublished": "2026-09-11T01:45:58.539Z",
        "dateReserved": "2026-08-22T23:34:10.554Z",
        "dateUpdated": "2026-09-11T20:04:15.477Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-78130 (GCVE-0-2026-78130)

    Vulnerability from cvelistv5 – Published: 2026-09-11 01:43 – Updated: 2026-09-15 15:30
    VLAI
    Summary
    strongSwan 4.2.0 through 6.0.7 has a NULL pointer dereference in the x509 plugin's attribute certificate parser.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-15 15:30 UTC
    CWE
    • CWE-476 - NULL Pointer Dereference
    Impacted products
    Vendor Product Version
    strongSwan strongSwan Affected: 4.2.0 , < 6.1.0 (semver)
        cpe:2.3:a:strongswan:strongswan:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-78130",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-15T15:30:00.943919Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-15T15:30:16.065Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "strongSwan",
              "vendor": "strongSwan",
              "versions": [
                {
                  "lessThan": "6.1.0",
                  "status": "affected",
                  "version": "4.2.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:strongswan:strongswan:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.1.0",
                      "versionStartIncluding": "4.2.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "strongSwan 4.2.0 through 6.0.7 has a NULL pointer dereference in the x509 plugin\u0027s attribute certificate parser."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-476",
                  "description": "CWE-476 NULL Pointer Dereference",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-11T01:43:43.954Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://github.com/strongswan/strongswan/releases/tag/6.1.0"
            },
            {
              "url": "https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78130).html"
            }
          ],
          "x_generator": {
            "engine": "CVE-Request-form 0.0.1"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2026-78130",
        "datePublished": "2026-09-11T01:43:43.954Z",
        "dateReserved": "2026-08-22T23:32:38.352Z",
        "dateUpdated": "2026-09-15T15:30:16.065Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-78129 (GCVE-0-2026-78129)

    Vulnerability from cvelistv5 – Published: 2026-09-11 01:40 – Updated: 2026-09-11 14:16
    VLAI
    Summary
    strongSwan 4.6.2 through 6.0.7 has an infinite loop in PKCS#5 decryption.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-11 14:16 UTC
    CWE
    • CWE-835 - Loop with Unreachable Exit Condition ('Infinite Loop')
    Impacted products
    Vendor Product Version
    strongSwan strongSwan Affected: 4.6.2 , < 6.1.0 (semver)
        cpe:2.3:a:strongswan:strongswan:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-78129",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-11T14:16:33.445371Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-11T14:16:41.560Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "strongSwan",
              "vendor": "strongSwan",
              "versions": [
                {
                  "lessThan": "6.1.0",
                  "status": "affected",
                  "version": "4.6.2",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:strongswan:strongswan:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.1.0",
                      "versionStartIncluding": "4.6.2",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "strongSwan 4.6.2 through 6.0.7 has an infinite loop in PKCS#5 decryption."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 5.9,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-835",
                  "description": "CWE-835 Loop with Unreachable Exit Condition (\u0027Infinite Loop\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-11T01:40:01.247Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://github.com/strongswan/strongswan/releases/tag/6.1.0"
            },
            {
              "url": "https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78129).html"
            }
          ],
          "x_generator": {
            "engine": "CVE-Request-form 0.0.1"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2026-78129",
        "datePublished": "2026-09-11T01:40:01.247Z",
        "dateReserved": "2026-08-22T23:30:57.401Z",
        "dateUpdated": "2026-09-11T14:16:41.560Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-78127 (GCVE-0-2026-78127)

    Vulnerability from cvelistv5 – Published: 2026-09-11 01:37 – Updated: 2026-09-11 17:22
    VLAI
    Summary
    libcharon in strongSwan 4.1.2 through 6.0.7 has a missing release of memory after its effective lifetime in the IKE message parser.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-11 17:20 UTC
    CWE
    • CWE-401 - Missing Release of Memory after Effective Lifetime
    Impacted products
    Vendor Product Version
    strongSwan strongSwan Affected: 4.1.2 , < 6.1.0 (semver)
        cpe:2.3:a:strongswan:strongswan:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-78127",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-11T17:20:25.810055Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-11T17:22:42.244Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "strongSwan",
              "vendor": "strongSwan",
              "versions": [
                {
                  "lessThan": "6.1.0",
                  "status": "affected",
                  "version": "4.1.2",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:strongswan:strongswan:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.1.0",
                      "versionStartIncluding": "4.1.2",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "libcharon in strongSwan 4.1.2 through 6.0.7 has a missing release of memory after its effective lifetime in the IKE message parser."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 3.7,
                "baseSeverity": "LOW",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-401",
                  "description": "CWE-401 Missing Release of Memory after Effective Lifetime",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-11T01:37:05.572Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://github.com/strongswan/strongswan/releases/tag/6.1.0"
            },
            {
              "url": "https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78127).html"
            }
          ],
          "x_generator": {
            "engine": "CVE-Request-form 0.0.1"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2026-78127",
        "datePublished": "2026-09-11T01:37:05.572Z",
        "dateReserved": "2026-08-22T23:29:27.183Z",
        "dateUpdated": "2026-09-11T17:22:42.244Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-78126 (GCVE-0-2026-78126)

    Vulnerability from cvelistv5 – Published: 2026-09-11 01:33 – Updated: 2026-09-14 18:18
    VLAI
    Summary
    strongSwan 4.1.10 through 6.0.7 allows a NULL pointer dereference in the eap-aka plugin.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-14 14:57 UTC
    CWE
    • CWE-476 - NULL Pointer Dereference
    Impacted products
    Vendor Product Version
    strongSwan strongSwan Affected: 4.1.10 , < 6.1.0 (semver)
        cpe:2.3:a:strongswan:strongswan:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-78126",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-14T14:57:04.257804Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-14T18:18:37.226Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "strongSwan",
              "vendor": "strongSwan",
              "versions": [
                {
                  "lessThan": "6.1.0",
                  "status": "affected",
                  "version": "4.1.10",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:strongswan:strongswan:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.1.0",
                      "versionStartIncluding": "4.1.10",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "strongSwan 4.1.10 through 6.0.7 allows a NULL pointer dereference in the eap-aka plugin."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 5.9,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-476",
                  "description": "CWE-476 NULL Pointer Dereference",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-11T01:33:50.717Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://github.com/strongswan/strongswan/releases/tag/6.1.0"
            },
            {
              "url": "https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78126).html"
            }
          ],
          "x_generator": {
            "engine": "CVE-Request-form 0.0.1"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2026-78126",
        "datePublished": "2026-09-11T01:33:50.717Z",
        "dateReserved": "2026-08-22T23:27:32.767Z",
        "dateUpdated": "2026-09-14T18:18:37.226Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-78124 (GCVE-0-2026-78124)

    Vulnerability from cvelistv5 – Published: 2026-09-11 01:30 – Updated: 2026-09-11 20:05
    VLAI
    Summary
    strongSwan 5.0.2 through 6.0.7 allows PKCS#7 certificate enumeration in the openssl plugin that leads to a lack of release of memory after its effective lifetime.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-11 20:05 UTC
    CWE
    • CWE-401 - Missing Release of Memory after Effective Lifetime
    Impacted products
    Vendor Product Version
    strongSwan strongSwan Affected: 5.0.2 , < 6.1.0 (semver)
        cpe:2.3:a:strongswan:strongswan:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-78124",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-11T20:05:14.510796Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-11T20:05:22.532Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "strongSwan",
              "vendor": "strongSwan",
              "versions": [
                {
                  "lessThan": "6.1.0",
                  "status": "affected",
                  "version": "5.0.2",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:strongswan:strongswan:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.1.0",
                      "versionStartIncluding": "5.0.2",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "strongSwan 5.0.2 through 6.0.7 allows PKCS#7 certificate enumeration in the openssl plugin that leads to a lack of release of memory after its effective lifetime."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 3.7,
                "baseSeverity": "LOW",
                "confidentialityImpact": "LOW",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-401",
                  "description": "CWE-401 Missing Release of Memory after Effective Lifetime",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-11T01:30:47.699Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://github.com/strongswan/strongswan/releases/tag/6.1.0"
            },
            {
              "url": "https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78124).html"
            }
          ],
          "x_generator": {
            "engine": "CVE-Request-form 0.0.1"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2026-78124",
        "datePublished": "2026-09-11T01:30:47.699Z",
        "dateReserved": "2026-08-22T23:25:55.893Z",
        "dateUpdated": "2026-09-11T20:05:22.532Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-78123 (GCVE-0-2026-78123)

    Vulnerability from cvelistv5 – Published: 2026-09-11 01:26 – Updated: 2026-09-15 15:25
    VLAI
    Summary
    strongSwan 5.0.2 through 6.0.7 has an Expired Pointer Dereference in PKCS#7 parsing in the openssl plugin.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-15 15:25 UTC
    CWE
    • CWE-825 - Expired Pointer Dereference
    Impacted products
    Vendor Product Version
    strongSwan strongSwan Affected: 5.0.2 , < 6.1.0 (semver)
        cpe:2.3:a:strongswan:strongswan:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-78123",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-15T15:25:21.384557Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-15T15:25:26.253Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "strongSwan",
              "vendor": "strongSwan",
              "versions": [
                {
                  "lessThan": "6.1.0",
                  "status": "affected",
                  "version": "5.0.2",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:strongswan:strongswan:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.1.0",
                      "versionStartIncluding": "5.0.2",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "strongSwan 5.0.2 through 6.0.7 has an Expired Pointer Dereference in PKCS#7 parsing in the openssl plugin."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 5.9,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-825",
                  "description": "CWE-825 Expired Pointer Dereference",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-11T01:26:21.394Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://github.com/strongswan/strongswan/releases/tag/6.1.0"
            },
            {
              "url": "https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78123).html"
            }
          ],
          "x_generator": {
            "engine": "CVE-Request-form 0.0.1"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2026-78123",
        "datePublished": "2026-09-11T01:26:21.394Z",
        "dateReserved": "2026-08-22T23:24:13.793Z",
        "dateUpdated": "2026-09-15T15:25:26.253Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-47895 (GCVE-0-2026-47895)

    Vulnerability from cvelistv5 – Published: 2026-08-22 00:00 – Updated: 2026-08-24 13:01
    VLAI
    Summary
    In strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-Identities that result in an empty but non-NULL encoding are not correctly cloned and trigger a double-free once the duplicates are destroyed.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-24 12:43 UTC
    CWE
    Impacted products
    Vendor Product Version
    strongSwan strongSwan Affected: 4.3.3 , < 6.0.7 (semver)
        cpe:2.3:a:strongswan:strongswan:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-47895",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-24T12:43:42.540667Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-24T13:01:23.595Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "strongSwan",
              "vendor": "strongSwan",
              "versions": [
                {
                  "lessThan": "6.0.7",
                  "status": "affected",
                  "version": "4.3.3",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:strongswan:strongswan:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.0.7",
                      "versionStartIncluding": "4.3.3",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-Identities that result in an empty but non-NULL encoding are not correctly cloned and trigger a double-free once the duplicates are destroyed."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-415",
                  "description": "CWE-415 Double Free",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-23T01:52:41.416Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://www.strongswan.org/download.html"
            },
            {
              "url": "https://github.com/strongswan/strongswan/releases/tag/6.0.7"
            }
          ],
          "x_generator": {
            "engine": "enrichogram 0.0.1"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2026-47895",
        "datePublished": "2026-08-22T00:00:00.000Z",
        "dateReserved": "2026-05-20T00:00:00.000Z",
        "dateUpdated": "2026-08-24T13:01:23.595Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-25075 (GCVE-0-2026-25075)

    Vulnerability from cvelistv5 – Published: 2026-03-23 18:33 – Updated: 2026-07-14 15:53
    VLAI
    Title
    strongSwan 4.5.0 < 6.0.5 EAP-TTLS AVP Parsing Integer Underflow
    Summary
    strongSwan versions 4.5.0 prior to 6.0.5 contain an integer underflow vulnerability in the EAP-TTLS AVP parser that allows unauthenticated remote attackers to cause a denial of service by sending crafted AVP data with invalid length fields during IKEv2 authentication. Attackers can exploit the failure to validate AVP length fields before subtraction to trigger excessive memory allocation or NULL pointer dereference, crashing the charon IKE daemon.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-03-25 14:29 UTC
    CWE
    • CWE-191 - Integer Underflow (Wrap or Wraparound)
    • CWE-476 - NULL Pointer Dereference (CWE-476)
    Impacted products
    Vendor Product Version
    strongSwan strongSwan Affected: 4.5.0 , < 6.0.5 (semver)
        cpe:2.3:a:strongswan:strongswan:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-03-23 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-25075",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-03-25T14:29:53.640147Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-05-06T14:41:06.076Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2026-03-27T19:17:30.660Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://lists.debian.org/debian-lts-announce/2026/03/msg00016.html"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:github/strongswan/strongswan",
              "product": "strongSwan",
              "repo": "https://github.com/strongswan/strongswan",
              "vendor": "strongSwan",
              "versions": [
                {
                  "lessThan": "6.0.5",
                  "status": "affected",
                  "version": "4.5.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:strongswan:strongswan:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.0.5",
                      "versionStartIncluding": "4.5.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Kazuma Matsumoto, a security researcher at GMO Cybersecurity by IERAE, Inc."
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "VulnCheck"
            }
          ],
          "datePublic": "2026-03-23T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "strongSwan versions 4.5.0 prior to 6.0.5 contain an integer underflow vulnerability in the EAP-TTLS AVP parser that allows unauthenticated remote attackers to cause a denial of service by sending crafted AVP data with invalid length fields during IKEv2 authentication. Attackers can exploit the failure to validate AVP length fields before subtraction to trigger excessive memory allocation or NULL pointer dereference, crashing the charon IKE daemon."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-191",
                  "description": "CWE-191: Integer Underflow (Wrap or Wraparound)",
                  "lang": "en",
                  "type": "CWE"
                },
                {
                  "cweId": "CWE-476",
                  "description": "NULL Pointer Dereference (CWE-476)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-07-14T15:53:40.465Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory",
                "exploit"
              ],
              "url": "https://www.strongswan.org/blog/2026/03/23/strongswan-vulnerability-(cve-2026-25075).html"
            },
            {
              "tags": [
                "release-notes"
              ],
              "url": "https://www.strongswan.org/blog/2026/03/23/strongswan-6.0.5-released.html"
            },
            {
              "tags": [
                "technical-description",
                "exploit"
              ],
              "url": "https://y637f9qq2x.com/posts/cve-2026-25075/"
            },
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/strongswan-eap-ttls-avp-parsing-integer-underflow"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "strongSwan 4.5.0 \u003c 6.0.5 EAP-TTLS AVP Parsing Integer Underflow",
          "x_generator": {
            "engine": "Vulnogram 1.0.1"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-25075",
        "datePublished": "2026-03-23T18:33:10.952Z",
        "dateReserved": "2026-01-28T21:47:35.121Z",
        "dateUpdated": "2026-07-14T15:53:40.465Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-25998 (GCVE-0-2026-25998)

    Vulnerability from cvelistv5 – Published: 2026-02-19 15:51 – Updated: 2026-02-20 15:42
    VLAI
    Title
    strongMan vulnerable to private credential recovery due to key and counter reuse
    Summary
    strongMan is a management interface for strongSwan, an OpenSource IPsec-based VPN. When storing credentials in the database (private keys, EAP secrets), strongMan encrypts the corresponding database fields. So far it used AES in CTR mode with a global database key. Together with an initialization vector (IV), a key stream is generated to encrypt the data in the database fields. But because strongMan did not generate individual IVs, every database field was encrypted using the same key stream. An attacker that has access to the database can use this to recover the encrypted credentials. In particular, because certificates, which have to be considered public information, are also encrypted using the same mechanism, an attacker can directly recover a large chunk of the key stream, which allows them to decrypt basically all other secrets especially ECDSA private keys and EAP secrets, which are usually a lot shorter. Version 0.2.0 fixes the issue by switching to AES-GCM-SIV encryption with a random nonce and an individually derived encryption key, using HKDF, for each encrypted value. Database migrations are provided to automatically re-encrypt all credentials.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-02-20 15:32 UTC
    CWE
    • CWE-323 - Reusing a Nonce, Key Pair in Encryption
    • CWE-1204 - Generation of Weak Initialization Vector (IV)
    References
    Impacted products
    Vendor Product Version
    strongswan strongMan Affected: < 0.2.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-25998",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-02-20T15:32:21.931190Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-02-20T15:42:52.654Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "strongMan",
              "vendor": "strongswan",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 0.2.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "strongMan is a management interface for strongSwan, an OpenSource IPsec-based VPN. When storing credentials in the database (private keys, EAP secrets), strongMan encrypts the corresponding database fields. So far it used AES in CTR mode with a global database key. Together with an initialization vector (IV), a key stream is generated to encrypt the data in the database fields. But because strongMan did not generate individual IVs, every database field was encrypted using the same key stream. An attacker that has access to the database can use this to recover the encrypted credentials. In particular, because certificates, which have to be considered public information, are also encrypted using the same mechanism, an attacker can directly recover a large chunk of the key stream, which allows them to decrypt basically all other secrets especially ECDSA private keys and EAP secrets, which are usually a lot shorter. Version 0.2.0 fixes the issue by switching to AES-GCM-SIV encryption with a random nonce and an individually derived encryption key, using HKDF, for each encrypted value. Database migrations are provided to automatically re-encrypt all credentials."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "NONE"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-323",
                  "description": "CWE-323: Reusing a Nonce, Key Pair in Encryption",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-1204",
                  "description": "CWE-1204: Generation of Weak Initialization Vector (IV)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-02-19T15:53:30.113Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/strongswan/strongMan/security/advisories/GHSA-88w4-jv97-c8xr",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/strongswan/strongMan/security/advisories/GHSA-88w4-jv97-c8xr"
            }
          ],
          "source": {
            "advisory": "GHSA-88w4-jv97-c8xr",
            "discovery": "UNKNOWN"
          },
          "title": "strongMan vulnerable to private credential recovery due to key and counter reuse"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-25998",
        "datePublished": "2026-02-19T15:51:35.349Z",
        "dateReserved": "2026-02-09T17:41:55.859Z",
        "dateUpdated": "2026-02-20T15:42:52.654Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-62291 (GCVE-0-2025-62291)

    Vulnerability from cvelistv5 – Published: 2026-01-16 00:00 – Updated: 2026-01-16 19:07
    VLAI
    Summary
    In the eap-mschapv2 plugin (client-side) in strongSwan before 6.0.3, a malicious EAP-MSCHAPv2 server can send a crafted message of size 6 through 8, and cause an integer underflow that potentially results in a heap-based buffer overflow.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-01-16 18:50 UTC
    CWE
    • CWE-191 - Integer Underflow (Wrap or Wraparound)
    Impacted products
    Vendor Product Version
    strongSwan strongSwan Affected: 4.2.12 , < 6.0.3 (semver)
        cpe:2.3:a:strongswan:strongswan:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-62291",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-01-16T18:50:33.538280Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-01-16T18:51:12.740Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2026-01-16T19:07:43.455Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/11/msg00002.html"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "strongSwan",
              "vendor": "strongSwan",
              "versions": [
                {
                  "lessThan": "6.0.3",
                  "status": "affected",
                  "version": "4.2.12",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:strongswan:strongswan:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.0.3",
                      "versionStartIncluding": "4.2.12",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In the eap-mschapv2 plugin (client-side) in strongSwan before 6.0.3, a malicious EAP-MSCHAPv2 server can send a crafted message of size 6 through 8, and cause an integer underflow that potentially results in a heap-based buffer overflow."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 8.1,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-191",
                  "description": "CWE-191 Integer Underflow (Wrap or Wraparound)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-01-16T18:23:50.089Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://github.com/strongswan/strongswan/releases"
            },
            {
              "url": "https://github.com/strongswan/strongswan/commits/master/src/libcharon/plugins/eap_mschapv2"
            },
            {
              "url": "https://www.strongswan.org/blog/2025/10/27/strongswan-vulnerability-%28cve-2025-62291%29.html"
            }
          ],
          "x_generator": {
            "engine": "enrichogram 0.0.1"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2025-62291",
        "datePublished": "2026-01-16T00:00:00.000Z",
        "dateReserved": "2025-10-10T00:00:00.000Z",
        "dateUpdated": "2026-01-16T19:07:43.455Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2022-4967 (GCVE-0-2022-4967)

    Vulnerability from cvelistv5 – Published: 2024-05-13 12:09 – Updated: 2025-02-13 16:38
    VLAI
    Summary
    strongSwan versions 5.9.2 through 5.9.5 are affected by authorization bypass through improper validation of certificate with host mismatch (CWE-297). When certificates are used to authenticate clients in TLS-based EAP methods, the IKE or EAP identity supplied by a client is not enforced to be contained in the client's certificate. So clients can authenticate with any trusted certificate and claim an arbitrary IKE/EAP identity as their own. This is problematic if the identity is used to make policy decisions. A fix was released in strongSwan version 5.9.6 in August 2022 (e4b4aabc4996fc61c37deab7858d07bc4d220136).
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-05-17 13:10 UTC
    CWE
    Impacted products
    Vendor Product Version
    strongSwan strongSwan Affected: 5.9.2 , < 5.9.6 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2022-4967",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-05-17T13:10:42.421746Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-04T17:16:33.158Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T01:55:46.125Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "patch",
                  "x_transferred"
                ],
                "url": "https://github.com/strongswan/strongswan/commit/e4b4aabc4996fc61c37deab7858d07bc4d220136"
              },
              {
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://www.strongswan.org/blog/2024/05/13/strongswan-vulnerability-(cve-2022-4967).html"
              },
              {
                "tags": [
                  "issue-tracking",
                  "x_transferred"
                ],
                "url": "https://www.cve.org/CVERecord?id=CVE-2022-4967"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://security.netapp.com/advisory/ntap-20240614-0006/"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "packageName": "strongswan",
              "platforms": [
                "Linux"
              ],
              "product": "strongSwan",
              "repo": "https://github.com/strongswan/strongswan",
              "vendor": "strongSwan",
              "versions": [
                {
                  "lessThan": "5.9.6",
                  "status": "affected",
                  "version": "5.9.2",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Jan Schermer"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "strongSwan versions 5.9.2 through 5.9.5 are affected by authorization bypass through improper validation of certificate with host mismatch (CWE-297). When certificates are used to authenticate clients in TLS-based EAP methods, the IKE or EAP identity supplied by a client is not enforced to be contained in the client\u0027s certificate. So clients can authenticate with any trusted certificate and claim an arbitrary IKE/EAP identity as their own. This is problematic if the identity is used to make policy decisions. A fix was released in strongSwan version 5.9.6 in August 2022 (e4b4aabc4996fc61c37deab7858d07bc4d220136)."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.7,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-297",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-06-14T13:06:08.293Z",
            "orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
            "shortName": "canonical"
          },
          "references": [
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/strongswan/strongswan/commit/e4b4aabc4996fc61c37deab7858d07bc4d220136"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.strongswan.org/blog/2024/05/13/strongswan-vulnerability-(cve-2022-4967).html"
            },
            {
              "tags": [
                "issue-tracking"
              ],
              "url": "https://www.cve.org/CVERecord?id=CVE-2022-4967"
            },
            {
              "url": "https://security.netapp.com/advisory/ntap-20240614-0006/"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
        "assignerShortName": "canonical",
        "cveId": "CVE-2022-4967",
        "datePublished": "2024-05-13T12:09:19.104Z",
        "dateReserved": "2024-04-19T18:02:23.578Z",
        "dateUpdated": "2025-02-13T16:38:39.882Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2018-5389 (GCVE-0-2018-5389)

    Vulnerability from cvelistv5 – Published: 2018-09-06 21:00 – Updated: 2024-08-05 05:33
    VLAI
    Title
    CVE-2018-5389
    Summary
    The Internet Key Exchange v1 main mode is vulnerable to offline dictionary or brute force attacks. Reusing a key pair across different versions and modes of IKE could lead to cross-protocol authentication bypasses. It is well known, that the aggressive mode of IKEv1 PSK is vulnerable to offline dictionary or brute force attacks. For the main mode, however, only an online attack against PSK authentication was thought to be feasible. This vulnerability could allow an attacker to recover a weak Pre-Shared Key or enable the impersonation of a victim host or network.
    Severity
    No CVSS data available.
    Impacted products
    Vendor Product Version
    strongSwan Strongswan Affected: 5.5.1
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-05T05:33:44.296Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.usenix.org/system/files/conference/usenixsecurity18/sec18-felsch.pdf"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.kb.cert.org/vuls/id/857035"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://web-in-security.blogspot.com/2018/08/practical-dictionary-attack-on-ipsec-ike.html"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://blogs.cisco.com/security/great-cipher-but-where-did-you-get-that-key"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://my.f5.com/manage/s/article/K42378447"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Strongswan",
              "vendor": "strongSwan",
              "versions": [
                {
                  "status": "affected",
                  "version": "5.5.1"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Internet Key Exchange v1 main mode is vulnerable to offline dictionary or brute force attacks. Reusing a key pair across different versions and modes of IKE could lead to cross-protocol authentication bypasses. It is well known, that the aggressive mode of IKEv1 PSK is vulnerable to offline dictionary or brute force attacks. For the main mode, however, only an online attack against PSK authentication was thought to be feasible. This vulnerability could allow an attacker to recover a weak Pre-Shared Key or enable the impersonation of a victim host or network."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-521 Weak Password Requirements",
                  "lang": "en"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "description": "CWE-323 Reusing a Nonce, Key Pair in Encryption",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-06-24T19:08:15.699Z",
            "orgId": "37e5125f-f79b-445b-8fad-9564f167944b",
            "shortName": "certcc"
          },
          "references": [
            {
              "url": "https://www.usenix.org/system/files/conference/usenixsecurity18/sec18-felsch.pdf"
            },
            {
              "url": "https://www.kb.cert.org/vuls/id/857035"
            },
            {
              "url": "https://web-in-security.blogspot.com/2018/08/practical-dictionary-attack-on-ipsec-ike.html"
            },
            {
              "url": "https://blogs.cisco.com/security/great-cipher-but-where-did-you-get-that-key"
            },
            {
              "url": "https://my.f5.com/manage/s/article/K42378447"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "CVE-2018-5389",
          "x_generator": {
            "engine": "VINCE 3.0.4",
            "env": "prod",
            "origin": "https://cveawg.mitre.org/api/cve/CVE-2018-5389"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "37e5125f-f79b-445b-8fad-9564f167944b",
        "assignerShortName": "certcc",
        "cveId": "CVE-2018-5389",
        "datePublished": "2018-09-06T21:00:00.000Z",
        "dateReserved": "2018-01-12T00:00:00.000Z",
        "dateUpdated": "2024-08-05T05:33:44.296Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2018-5388 (GCVE-0-2018-5388)

    Vulnerability from cvelistv5 – Published: 2018-05-31 00:00 – Updated: 2024-08-05 05:33
    VLAI
    Summary
    In stroke_socket.c in strongSwan before 5.6.3, a missing packet length check could allow a buffer underflow, which may lead to resource exhaustion and denial of service while reading from the socket.
    Severity
    No CVSS data available.
    CWE
    Impacted products
    Vendor Product Version
    strongSwan strongSwan Affected: 5.6.3 , < 5.6.3 (custom)
    Create a notification for this product.
    Date Public
    2018-05-22 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-05T05:33:44.315Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "VU#338343",
                "tags": [
                  "third-party-advisory",
                  "x_transferred"
                ],
                "url": "http://www.kb.cert.org/vuls/id/338343"
              },
              {
                "name": "GLSA-201811-16",
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://security.gentoo.org/glsa/201811-16"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.strongswan.org/?p=strongswan.git%3Ba=commitdiff%3Bh=0acd1ab4"
              },
              {
                "name": "104263",
                "tags": [
                  "vdb-entry",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/104263"
              },
              {
                "name": "USN-3771-1",
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://usn.ubuntu.com/3771-1/"
              },
              {
                "name": "DSA-4229",
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://www.debian.org/security/2018/dsa-4229"
              },
              {
                "name": "openSUSE-SU-2019:2594",
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00077.html"
              },
              {
                "name": "openSUSE-SU-2019:2598",
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00001.html"
              },
              {
                "name": "openSUSE-SU-2020:0403",
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00047.html"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "http://packetstormsecurity.com/files/172833/strongSwan-VPN-Charon-Server-Buffer-Overflow.html"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "strongSwan",
              "vendor": "strongSwan",
              "versions": [
                {
                  "lessThan": "5.6.3",
                  "status": "affected",
                  "version": "5.6.3",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "value": "Thanks to Kevin Backhouse for reporting this vulnerability."
            }
          ],
          "datePublic": "2018-05-22T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "In stroke_socket.c in strongSwan before 5.6.3, a missing packet length check could allow a buffer underflow, which may lead to resource exhaustion and denial of service while reading from the socket."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-124",
                  "description": "CWE-124",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-06-12T00:00:00.000Z",
            "orgId": "37e5125f-f79b-445b-8fad-9564f167944b",
            "shortName": "certcc"
          },
          "references": [
            {
              "name": "VU#338343",
              "tags": [
                "third-party-advisory"
              ],
              "url": "http://www.kb.cert.org/vuls/id/338343"
            },
            {
              "name": "GLSA-201811-16",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://security.gentoo.org/glsa/201811-16"
            },
            {
              "url": "https://git.strongswan.org/?p=strongswan.git%3Ba=commitdiff%3Bh=0acd1ab4"
            },
            {
              "name": "104263",
              "tags": [
                "vdb-entry"
              ],
              "url": "http://www.securityfocus.com/bid/104263"
            },
            {
              "name": "USN-3771-1",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://usn.ubuntu.com/3771-1/"
            },
            {
              "name": "DSA-4229",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.debian.org/security/2018/dsa-4229"
            },
            {
              "name": "openSUSE-SU-2019:2594",
              "tags": [
                "vendor-advisory"
              ],
              "url": "http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00077.html"
            },
            {
              "name": "openSUSE-SU-2019:2598",
              "tags": [
                "vendor-advisory"
              ],
              "url": "http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00001.html"
            },
            {
              "name": "openSUSE-SU-2020:0403",
              "tags": [
                "vendor-advisory"
              ],
              "url": "http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00047.html"
            },
            {
              "url": "http://packetstormsecurity.com/files/172833/strongSwan-VPN-Charon-Server-Buffer-Overflow.html"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "37e5125f-f79b-445b-8fad-9564f167944b",
        "assignerShortName": "certcc",
        "cveId": "CVE-2018-5388",
        "datePublished": "2018-05-31T00:00:00.000Z",
        "dateReserved": "2018-01-12T00:00:00.000Z",
        "dateUpdated": "2024-08-05T05:33:44.315Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }