State Issues in strongSwan - CVE-2021-45079

 

State Issues in strongSwan - CVE-2021-45079

Published: January 25, 2022


Vulnerability identifier: #VU59994
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-45079
CWE-ID: CWE-371
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication.

The vulnerability exists due to improper handling of EAP-Success messages. A remote attacker can send a specially crafted (early) EAP-Success message to the affected system and bypass authentication or perform a denial of service attack.


Affected software

strongSwan
Gentoo Linux
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Enterprise Storage
Fedora
SUSE Linux Enterprise Point of Sale
SUSE Linux Enterprise Debuginfo
SUSE Linux Enterprise Server
Ubuntu
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Workstation Extension
SUSE Linux Enterprise Server for SAP Applications
openEuler
strongswan (Debian package)
SUSE Linux Enterprise Module for Packagehub Subpackages
strongswan-debuginfo
strongswan-doc
strongswan
strongswan-debugsource
libstrongswan (Ubuntu package)
strongswan (Ubuntu package)
strongswan-help
strongswan-tnc-imcvs
strongswan-sqlite
strongswan-charon-nm
strongswan-libipsec
strongswan-libs0-debuginfo
strongswan-libs0
strongswan-ipsec-debuginfo
strongswan-ipsec
strongswan-hmac
strongswan-nm
strongswan-nm-debuginfo
net-vpn/strongswan
PowerStore T

How to mitigate CVE-2021-45079

Install updates from vendor's website.

strongSwan - update to 5.9.5
strongswan (Debian package) - addressed in versions 5.7.2-1+deb10u2, 5.9.1-1+deb11u2
PowerStore T - update to 3.5.0.1-2083289
strongswan-debuginfo - addressed in versions 4.4.0-6.36.12.1, 5.8.2-4.17.1, 5.8.2-11.24.1
strongswan-doc - addressed in versions 4.4.0-6.36.12.1, 5.8.2-4.17.1, 5.8.2-11.24.1
strongswan - addressed in versions 4.4.0-6.36.12.1, 5.8.2-4.17.1, 5.8.2-11.24.1
strongswan-debugsource - addressed in versions 4.4.0-6.36.12.1, 5.8.2-4.17.1, 5.8.2-11.24.1
libstrongswan (Ubuntu package) - addressed in versions 5.3.51ubuntu3.8+esm2, 5.6.2-1ubuntu2.8, 5.8.2-1ubuntu3.4, 5.9.1-1ubuntu3.2
strongswan (Ubuntu package) - addressed in versions 5.3.51ubuntu3.8+esm2, 5.6.2-1ubuntu2.8, 5.8.2-1ubuntu3.4, 5.9.1-1ubuntu3.2
strongswan - addressed in versions 5.7.2-8, 5.7.2-12
strongswan-debugsource - addressed in versions 5.7.2-8, 5.7.2-12
strongswan-debuginfo - addressed in versions 5.7.2-8, 5.7.2-12
strongswan-help - update to 5.7.2-8
strongswan-tnc-imcvs - update to 5.7.2-12
strongswan-sqlite - update to 5.7.2-12
strongswan-charon-nm - update to 5.7.2-12
strongswan-libipsec - update to 5.7.2-12
strongswan-libs0-debuginfo - addressed in versions 5.8.2-4.17.1, 5.8.2-11.24.1
strongswan-libs0 - addressed in versions 5.8.2-4.17.1, 5.8.2-11.24.1
strongswan-ipsec-debuginfo - addressed in versions 5.8.2-4.17.1, 5.8.2-11.24.1
strongswan-ipsec - addressed in versions 5.8.2-4.17.1, 5.8.2-11.24.1
strongswan-hmac - addressed in versions 5.8.2-4.17.1, 5.8.2-11.24.1
strongswan-nm - update to 5.8.2-11.24.1
strongswan-nm-debuginfo - update to 5.8.2-11.24.1
strongswan - addressed in versions 5.9.5-2.el8, 5.9.5-2.el9, 5.9.5-2.fc34, 5.9.5-2.fc35
net-vpn/strongswan - update to 5.9.10

External References

Related Security Bulletins