PT-2026-20491 · Strongman+1 · Strongman+1
Tobiasbrunner
·
Published
2026-02-18
·
Updated
2026-02-23
·
CVE-2026-25998
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
strongMan versions prior to 0.2.0
Description
strongMan, a management interface for strongSwan, improperly encrypted credentials stored in its database. The software used AES in CTR mode with a global database key and a consistent initialization vector (IV) for all database fields. This allowed an attacker with database access to recover encrypted credentials, including certificates, ECDSA private keys, and EAP secrets. Because certificates are considered public information, an attacker could recover a significant portion of the key stream, facilitating decryption of other sensitive data. The API endpoint used for credential storage was not specified. The vulnerable parameter was the database fields containing credentials (
private keys, EAP secrets).Recommendations
Upgrade to strongMan version 0.2.0 or later.
Run the provided database migrations to re-encrypt all credentials.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Strongman
Strongswan