PT-2024-11905 · Unknown+2 · Strongswan+2
Jan Schermer
·
Published
2024-05-13
·
Updated
2025-11-06
·
CVE-2022-4967
CVSS v3.1
7.7
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
strongSwan versions 5.9.2 through 5.9.5
Description
The issue is related to authorization bypass through improper validation of certificates with host mismatch. When certificates are used to authenticate clients in TLS-based EAP methods, the IKE or EAP identity supplied by a client is not enforced to be contained in the client's certificate. This allows clients to authenticate with any trusted certificate and claim an arbitrary IKE/EAP identity as their own, which is problematic if the identity is used to make policy decisions.
Recommendations
For strongSwan versions 5.9.2 through 5.9.5, update to version 5.9.6 or later to resolve the issue. As a temporary workaround, consider restricting the use of trusted certificates to minimize the risk of exploitation. Additionally, review and restrict any policy decisions based on IKE or EAP identities to prevent unauthorized access.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linuxmint
Ubuntu
Strongswan