strongSwan versions 5.9.2 through 5.9.5 are affected by authorization bypass through improper validation of certificate with host mismatch (CWE-297)
Published May 13, 2024
7.7
HIGHCVSS 3.1
EPSS 0.47%
Description
strongSwan versions 5.9.2 through 5.9.5 are affected by authorization bypass through improper validation of certificate with host mismatch (CWE-297). When certificates are used to authenticate clients in TLS-based EAP methods, the IKE or EAP identity supplied by a client is not enforced to be contained in the client's certificate. So clients can authenticate with any trusted certificate and claim an arbitrary IKE/EAP identity as their own. This is problematic if the identity is used to make policy decisions. A fix was released in strongSwan version 5.9.6 in August 2022 (e4b4aabc4996fc61c37deab7858d07bc4d220136).
Affected products
-
- Version 5.9.2StatusaffectedConstraints<5.9.6
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| strongSwan | strongSwan | n/a |
|
- ≥ 5.9.2 · < 5.9.6
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
No CWE recorded.
References (4)
- https://github.com/strongswan/strongswan/commit/e4b4aabc4996fc61c37deab7858d07bc4d220136 patch
- https://security.netapp.com/advisory/ntap-20240614-0006/ Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-4967 issue-trackingThird Party Advisory
- https://www.strongswan.org/blog/2024/05/13/strongswan-vulnerability-(cve-2022-4967).html vendor-advisoryMitigationVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/strongswan/strongswan/commit/e4b4aabc4996fc61c37deab7858d07bc4d220136 | patch | |
| https://security.netapp.com/advisory/ntap-20240614-0006/ | Third Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2022-4967 | issue-trackingThird Party Advisory | |
| https://www.strongswan.org/blog/2024/05/13/strongswan-vulnerability-(cve-2022-4967).html | vendor-advisoryMitigationVendor Advisory |
Change history (0)
No recorded changes yet.