Vulnerabilities in strongSwan
18 resultsVexday analysis
O strongSwan apresenta um perfil de risco contido com apenas 5 CVEs registradas na base, nenhuma delas sob exploração ativa no campo ou crítica. A fraqueza dominante identificada é CWE-191 (Integer Underflow), um tipo de vulnerabilidade clássica de underflow. Nenhuma vulnerabilidade foi publicada nos últimos 90 dias, indicando que o risco atual não é emergente.
CVE-2018-5388—In stroke_socket.c in strongSwan before 5.6.3, a missing packet length check could allow a buffer underflow, which may lead to resource exhaEPSS 4.0%CVE-2018-5389—CVE-2018-5389EPSS 3.0%CVE-2026-25075HIGHstrongSwan 4.5.0 < 6.0.5 EAP-TTLS AVP Parsing Integer UnderflowEPSS 1.0%CVE-2025-62291HIGHIn the eap-mschapv2 plugin (client-side) in strongSwan before 6.0.3, a malicious EAP-MSCHAPv2 server can send a crafted message of size 6 thEPSS 1.0%CVE-2026-47895HIGHIn strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-Identities that result in an empty but non-NULL encoding are EPSS 0.7%CVE-2022-4967HIGHstrongSwan versions 5.9.2 through 5.9.5 are affected by authorization bypass through improper validation of certificate with host mismatch (EPSS 0.5%CVE-2026-78133HIGHlibcharon in strongSwan 6.0.0 through 6.0.7 has a use-after-free in IKEv2 rekeying collision handling.EPSS 0.4%CVE-2026-78123MEDIUMstrongSwan 5.0.2 through 6.0.7 has an Expired Pointer Dereference in PKCS#7 parsing in the openssl plugin.EPSS 0.4%CVE-2026-78129MEDIUMstrongSwan 4.6.2 through 6.0.7 has an infinite loop in PKCS#5 decryption.EPSS 0.4%CVE-2026-78126MEDIUMstrongSwan 4.1.10 through 6.0.7 allows a NULL pointer dereference in the eap-aka plugin.EPSS 0.4%CVE-2026-78135MEDIUMlibcharon in strongSwan 5.9.7 through 6.0.7 mishandles behavioral workflow in the IKEv2 state machine. Because CREATE_CHILD_SA requests are EPSS 0.4%CVE-2026-78127LOWlibcharon in strongSwan 4.1.2 through 6.0.7 has a missing release of memory after its effective lifetime in the IKE message parser.EPSS 0.4%CVE-2026-25998HIGHstrongMan vulnerable to private credential recovery due to key and counter reuseEPSS 0.3%CVE-2026-78134HIGHstrongSwan 4.5.0 through 6.0.7 has Incorrect Access Control in the eap-ttls and eap-peap plugins because there can be a missing or mismatcheEPSS 0.3%CVE-2026-78130HIGHstrongSwan 4.2.0 through 6.0.7 has a NULL pointer dereference in the x509 plugin's attribute certificate parser.EPSS 0.3%CVE-2026-78132HIGHstrongSwan 5.1.3 through 6.0.7 has an infinite loop in the x509 plugin's attribute certificate parser for ietfAttrSyntax.EPSS 0.3%CVE-2026-78131LOWstrongSwan 4.2.0 through 6.0.7 has a missing release of memory after its effective lifetime in the x509 plugin's attribute certificate parseEPSS 0.2%CVE-2026-78124LOWstrongSwan 5.0.2 through 6.0.7 allows PKCS#7 certificate enumeration in the openssl plugin that leads to a lack of release of memory after iEPSS 0.2%