Description
strongSwan versions 5.9.2 through 5.9.5 are affected by authorization bypass through improper validation of certificate with host mismatch (CWE-297). When certificates are used to authenticate clients in TLS-based EAP methods, the IKE or EAP identity supplied by a client is not enforced to be contained in the client's certificate. So clients can authenticate with any trusted certificate and claim an arbitrary IKE/EAP identity as their own. This is problematic if the identity is used to make policy decisions. A fix was released in strongSwan version 5.9.6 in August 2022 (e4b4aabc4996fc61c37deab7858d07bc4d220136).
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-52219 | strongSwan versions 5.9.2 through 5.9.5 are affected by authorization bypass through improper validation of certificate with host mismatch (CWE-297). When certificates are used to authenticate clients in TLS-based EAP methods, the IKE or EAP identity supplied by a client is not enforced to be contained in the client's certificate. So clients can authenticate with any trusted certificate and claim an arbitrary IKE/EAP identity as their own. This is problematic if the identity is used to make policy decisions. A fix was released in strongSwan version 5.9.6 in August 2022 (e4b4aabc4996fc61c37deab7858d07bc4d220136). |
Ubuntu USN |
USN-6772-1 | strongSwan vulnerability |
References
History
Fri, 22 Aug 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | NVD-CWE-Other | |
| CPEs | cpe:2.3:a:strongswan:strongswan:*:*:*:*:*:*:*:* |
Status: PUBLISHED
Assigner: canonical
Published:
Updated: 2025-02-13T16:38:39.882Z
Reserved: 2024-04-19T18:02:23.578Z
Link: CVE-2022-4967
Updated: 2024-08-03T01:55:46.125Z
Status : Analyzed
Published: 2024-05-14T11:57:00.550
Modified: 2025-11-06T22:25:21.350
Link: CVE-2022-4967
No data.
OpenCVE Enrichment
Updated: 2025-07-12T22:44:40Z
Weaknesses
EUVD
Ubuntu USN