Vulnerability index

Browse CVEs

20 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Strongman HIGH 7.5
CVE-2026-25998

strongMan is a management interface for strongSwan, an OpenSource IPsec-based VPN. When storing credentials in the database (private keys, EAP secret…

Mitigation only
Fix from $1,950 2026-02-19
Strongswan MEDIUM 6.5
CVE-2022-4967

strongSwan versions 5.9.2 through 5.9.5 are affected by authorization bypass through improper validation of certificate with host mismatch (CWE-297).…

Fix: 5.9.6+
Fix from $1,600 2024-05-14
Strongswan CRITICAL 9.8
CVE-2023-41913

strongSwan before 5.9.12 has a buffer overflow and possible unauthenticated remote code execution via a DH public value that exceeds the internal buf…

Fix: 5.9.12+
Fix from $2,300 2023-12-07
Strongswan CRITICAL 9.8
CVE-2023-26463

strongSwan 5.9.8 and 5.9.9 potentially allows remote code execution because it uses a variable named "public" for two different purposes within the s…

Mitigation only
Fix from $2,300 2023-04-15
Strongswan MEDIUM 5.3
CVE-2018-6459

The rsa_pss_params_parse function in libstrongswan/credentials/keys/signature_params.c in strongSwan 5.6.1 allows remote attackers to cause a denial …

Mitigation only
Fix from $1,600 2018-02-20
Strongswan CRITICAL 9.8
CVE-2015-3991

strongSwan 5.2.2 and 5.3.0 allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code.

Mitigation only
Fix from $2,300 2017-09-07
Strongswan HIGH 7.5
CVE-2017-11185

The gmp plugin in strongSwan before 5.6.0 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a craf…

Fix: after 5.5.3
Fix from $1,950 2017-08-18
Strongswan HIGH 7.5
CVE-2017-9023

The ASN.1 parser in strongSwan before 5.5.3 improperly handles CHOICE types when the x509 plugin is enabled, which allows remote attackers to cause a…

Fix: after 5.5.2
Fix from $1,950 2017-06-08
Strongswan MEDIUM 6.4
CVE-2014-2338

IKEv2 in strongSwan 4.0.7 before 5.1.3 allows remote attackers to bypass authentication by rekeying an IKE_SA during (1) initiation or (2) re-authent…

Mitigation only
Fix from $1,600 2014-04-16
Strongswan MEDIUM 5.0
CVE-2013-6075

The compare_dn function in utils/identification.c in strongSwan 4.3.3 through 5.1.1 allows (1) remote attackers to cause a denial of service (out-of-…

Patch available
Fix from $1,600 2013-11-02
Strongswan MEDIUM 5.0
CVE-2013-6076

strongSwan 5.0.2 through 5.1.0 allows remote attackers to cause a denial of service (NULL pointer dereference and charon daemon crash) via a crafted …

Patch available
Fix from $1,600 2013-11-02
Strongswan MEDIUM 5.1
CVE-2013-2054

Buffer overflow in the atodn function in strongSwan 2.0.0 through 4.3.4, when Opportunistic Encryption is enabled and an RSA key is being used, allow…

Mitigation only
Fix from $1,600 2013-07-09
Strongswan HIGH 7.5
CVE-2012-2388

The GMP Plugin in strongSwan 4.2.0 through 4.6.3 allows remote attackers to bypass authentication via a (1) empty or (2) zeroed RSA signature, aka "R…

Mitigation only
Fix from $1,950 2012-06-27
Strongswan HIGH 7.5
CVE-2010-2628

The IKE daemon in strongSwan 4.3.x before 4.3.7 and 4.4.x before 4.4.1 does not properly check the return values of snprintf calls, which allows remo…

Patch available
Fix from $1,950 2010-08-20
Strongswan MEDIUM 5.0
CVE-2009-2661

The asn1_length function in strongSwan 2.8 before 2.8.11, 4.2 before 4.2.17, and 4.3 before 4.3.3 does not properly handle X.509 certificates with cr…

Patch available
Fix from $1,600 2009-08-04
Strongswan MEDIUM 5.0
CVE-2009-2185

The ASN.1 parser (pluto/asn1.c, libstrongswan/asn1/asn1.c, libstrongswan/asn1/asn1_parser.c) in (a) strongSwan 2.8 before 2.8.10, 4.2 before 4.2.16, …

Patch available
Fix from $1,600 2009-06-25
Strongswan MEDIUM 5.0
CVE-2009-1957

charon/sa/ike_sa.c in the charon daemon in strongSWAN before 4.3.1 allows remote attackers to cause a denial of service (NULL pointer dereference and…

Fix: after 4.3.0
Fix from $1,600 2009-06-08
Strongswan MEDIUM 5.0
CVE-2009-1958

charon/sa/tasks/child_create.c in the charon daemon in strongSWAN before 4.3.1 switches the NULL checks for TSi and TSr payloads, which allows remote…

Fix: after 4.2.9
Fix from $1,600 2009-06-08
Strongswan MEDIUM 5.0
CVE-2009-0790

The pluto IKE daemon in Openswan and Strongswan IPsec 2.6 before 2.6.21 and 2.4 before 2.4.14, and Strongswan 4.2 before 4.2.14 and 2.8 before 2.8.9,…

Patch available
Fix from $1,600 2009-04-01
Strongswan MEDIUM 5.0
CVE-2008-4551

strongSwan 4.2.6 and earlier allows remote attackers to cause a denial of service (daemon crash) via an IKE_SA_INIT message with a large number of NU…

Fix: after 4.2.6
Fix from $1,600 2008-10-14