← Back

CVE-2015-4171

nvd nist
Published: Jun 10, 2015Modified: May 6, 2026

JSON object

Loading...
2.6
Vector
AV:N/AC:H/Au:N/C:P/I:N/A:N
Exploitability: 4.9 / Impact: 2.9
Source: NVD

Description

strongSwan 4.3.0 through 5.x before 5.3.2 and strongSwan VPN Client before 1.4.6, when using EAP or pre-shared keys for authenticating an IKEv2 connection, does not enforce server authentication restrictions until the entire authentication process is complete, which allows remote servers to obtain credentials by using a valid certificate and then reading the responses.

Affected (39)

2 products
Strongswan Vpn Client
Strongswan
1 product
Ubuntu Linux
1 product
Debian Linux
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 1.4.5
Configuration B
4 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 14.04
Version 14.10
Version 15.04
Version 8.0
Configuration C
34 vulnerable
Vulnerable SoftwareAffected Versions
Strongswan
Version 4.3.0
Version 4.3.1
Version 4.3.2
Version 4.3.3
Version 4.3.4
Version 4.3.5
Version 4.3.6
Version 4.3.7
Version 4.4.0
Version 4.4.1
Version 4.5.0
Version 4.5.1
Version 4.5.2
Version 4.5.3
Version 4.6.0
Version 4.6.1
Version 4.6.2
Version 4.6.3
Version 4.6.4
Version 5.0.0
Version 5.0.1
Version 5.0.2
Version 5.0.3
Version 5.0.4
Version 5.1.0
Version 5.1.1
Version 5.1.2
Version 5.1.3
Version 5.2.0
Version 5.2.1
Version 5.2.2
Version 5.2.3
Version 5.3.0
Version 5.3.1

References (24)

Source: cve@mitre.org
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.