PT-2015-7707 · Strongswan+3 · Strongswan+3

Tobias Brunner

·

Published

2015-11-16

·

Updated

2024-06-15

·

CVE-2015-8023

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions strongSwan versions 4.2.12 through 5.x before 5.3.4
Description The issue concerns the server implementation of the EAP-MSCHAPv2 protocol in the eap-mschapv2 plugin. It does not properly validate local state, allowing remote attackers to bypass authentication. This can be achieved by sending an empty Success message in response to an initial Challenge message.
Recommendations For strongSwan versions 4.2.12 through 5.x before 5.3.4, update to version 5.3.4 or later to resolve the issue.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-2000
CVE-2015-8023
DLA-345-1
DSA-3398-1
OPENSUSE-SU-2024:10579-1
SUSE-SU-2015:2183-1
SUSE-SU-2015:2183-2
SUSE-SU-2015:2186-1
SUSE-SU-2015_2183-1
SUSE-SU-2015_2183-2
SUSE-SU-2015_2186-1
USN-2811-1

Affected Products

Alt Linux
Suse
Ubuntu
Strongswan