Описание
In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticating the client and (in the case of EAP methods with mutual authentication and EAP-only authentication for IKEv2) even without server authentication.
Уязвимые конфигурации
Одно из
Одно из
Одно из
EPSS
9.1 Critical
CVSS3
5.8 Medium
CVSS2
Дефекты
Связанные уязвимости
In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticating the client and (in the case of EAP methods with mutual authentication and EAP-only authentication for IKEv2) even without server authentication.
In strongSwan before 5.9.5 a malicious responder can send an EAP-Success message too early without actually authenticating the client and (in the case of EAP methods with mutual authentication and EAP-only authentication for IKEv2) even without server authentication.
In strongSwan before 5.9.5, a malicious responder can send an EAP-Succ ...
EPSS
9.1 Critical
CVSS3
5.8 Medium
CVSS2