PT-2015-6443 · Strongswan+3 · Strongswan Vpn Client+4

Alexander E. Patrakov

·

Published

2015-06-08

·

Updated

2024-06-15

·

CVE-2015-4171

CVSS v2.0

2.6

Low

VectorAV:N/AC:H/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions strongSwan versions 4.3.0 through 5.x before 5.3.2 strongSwan VPN Client versions prior to 1.4.6
Description The issue concerns the authentication process for IKEv2 connections using EAP or pre-shared keys. It does not enforce server authentication restrictions until the entire authentication process is complete. This allows remote servers to obtain credentials by using a valid certificate and then reading the responses.
Recommendations For strongSwan versions 4.3.0 through 5.x before 5.3.2, update to version 5.3.2 or later to resolve the issue. For strongSwan VPN Client versions prior to 1.4.6, update to version 1.4.6 or later to resolve the issue.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-1501
CVE-2015-4171
DLA-244-1
DSA-3282-1
OPENSUSE-SU-2024:10579-1
SUSE-SU-2015:1196-1
SUSE-SU-2015:1227-1
SUSE-SU-2015:1791-1
SUSE-SU-2015_1196-1
SUSE-SU-2015_1227-1
SUSE-SU-2015_1791-1
USN-2628-1

Affected Products

Alt Linux
Suse
Ubuntu
Strongswan
Strongswan Vpn Client