strongSwan 5.2.2 and 5.3.0 allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HStrongswan
APPStrongswan5.2.25.3.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEDoS
CWE
References
Related vulnerabilities
CVE-2023-41913CRITICAL9.8PL ✓same product
Buffer overflow w strongSwan umożliwiający zdalny RCE bez uwierzytelnienia
CVE-2023-26463CRITICAL9.8PL ✓same product
RCE w strongSwan przez błędne zarządzanie wskaźnikiem w EAP-TLS
CVE-2021-45079CRITICAL9.1PL ✓same product
strongSwan: przedwczesna wiadomość EAP-Success umożliwia ominięcie uwierzytelniania
CVE-2022-4967HIGH7.7same product
strongSwan versions 5.9.2 through 5.9.5 are affected by authorization bypass through improper validation of ce...
CVE-2022-40617HIGH7.5same product
strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sendi...