PT-2015-6443 · Strongswan+3 · Strongswan Vpn Client+4

Alexander E. Patrakov

·

Publicado

2015-06-08

·

Atualizado

2024-06-15

·

CVE-2015-4171

CVSS v2.0

2.6

Baixa

VetorAV:N/AC:H/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions strongSwan versions 4.3.0 through 5.x before 5.3.2 strongSwan VPN Client versions prior to 1.4.6
Description The issue concerns the authentication process for IKEv2 connections using EAP or pre-shared keys. It does not enforce server authentication restrictions until the entire authentication process is complete. This allows remote servers to obtain credentials by using a valid certificate and then reading the responses.
Recommendations For strongSwan versions 4.3.0 through 5.x before 5.3.2, update to version 5.3.2 or later to resolve the issue. For strongSwan VPN Client versions prior to 1.4.6, update to version 1.4.6 or later to resolve the issue.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2015-1501
CVE-2015-4171
DLA-244-1
DSA-3282-1
OPENSUSE-SU-2024:10579-1
SUSE-SU-2015:1196-1
SUSE-SU-2015:1227-1
SUSE-SU-2015:1791-1
SUSE-SU-2015_1196-1
SUSE-SU-2015_1227-1
SUSE-SU-2015_1791-1
USN-2628-1

Produtos afetados

Alt Linux
Suse
Ubuntu
Strongswan
Strongswan Vpn Client