Vulnerabilities > CVE-2021-45079 - NULL Pointer Dereference vulnerability in multiple products

047910
CVSS 9.1 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
HIGH

Summary

In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticating the client and (in the case of EAP methods with mutual authentication and EAP-only authentication for IKEv2) even without server authentication.

Vulnerable Configurations

Part Description Count
Application
Strongswan
101
Application
Fedoraproject
3
OS
Debian
3
OS
Fedoraproject
2
OS
Canonical
5

Common Weakness Enumeration (CWE)