SB2015111801 - Input validation error in strongSwan



SB2015111801 - Input validation error in strongSwan

Published: November 18, 2015 Updated: July 28, 2020

Security Bulletin ID SB2015111801
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Input validation error (CVE-ID: CVE-2015-8023)

The vulnerability allows a remote non-authenticated attacker to manipulate data.

The server implementation of the EAP-MSCHAPv2 protocol in the eap-mschapv2 plugin in strongSwan 4.2.12 through 5.x before 5.3.4 does not properly validate local state, which allows remote attackers to bypass authentication via an empty Success message in response to an initial Challenge message.


Remediation

Install update from vendor's website.