Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-45079

Опубликовано: 31 янв. 2022
Источник: ubuntu
Приоритет: high
CVSS2: 5.8
CVSS3: 9.1

Описание

In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticating the client and (in the case of EAP methods with mutual authentication and EAP-only authentication for IKEv2) even without server authentication.

РелизСтатусПримечание
bionic

released

5.6.2-1ubuntu2.8
devel

released

5.9.4-1ubuntu4
esm-infra-legacy/trusty

released

5.1.2-0ubuntu2.11+esm2
esm-infra/bionic

released

5.6.2-1ubuntu2.8
esm-infra/focal

released

5.8.2-1ubuntu3.4
esm-infra/xenial

released

5.3.5-1ubuntu3.8+esm2
fips-preview/jammy

released

5.9.4-1ubuntu4
fips-updates/bionic

released

5.6.2-1ubuntu2.fips.2.8.1
fips-updates/focal

released

5.8.2-1ubuntu3.fips.3.4.1
fips-updates/jammy

released

5.9.4-1ubuntu4

Показывать по

5.8 Medium

CVSS2

9.1 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.1
nvd
около 4 лет назад

In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticating the client and (in the case of EAP methods with mutual authentication and EAP-only authentication for IKEv2) even without server authentication.

CVSS3: 9.1
msrc
около 4 лет назад

Описание отсутствует

CVSS3: 9.1
debian
около 4 лет назад

In strongSwan before 5.9.5, a malicious responder can send an EAP-Succ ...

suse-cvrf
почти 4 года назад

Security update for strongswan

suse-cvrf
почти 4 года назад

Security update for strongswan

5.8 Medium

CVSS2

9.1 Critical

CVSS3