Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
strongSwan 4.3.0 through 5.x before 5.3.2 and strongSwan VPN Client before 1.4.6, when using EAP or pre-shared keys for authenticating an IKEv2 connection, does not enforce server authentication restrictions until the entire authentication process is complete, which allows remote servers to obtain credentials by using a valid certificate and then reading the responses.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
strongSwan和strongSwan VPN Client 安全漏洞
Vulnerability Description
strongSwan是瑞士软件开发者Andreas Steffen所维护的一套Linux平台使用的开源的基于IPsec的VPN解决方案。该方案包含X.509公开密钥证书、安全储存私钥、智能卡等认证机制。strongSwan VPN Client是其中的一个VPN客户端。 strongSwan 4.3.0版本至5.3.1版本和strongSwan VPN Client 1.4.6之前版本中存在安全漏洞,该漏洞源于程序在完成对IKEv2连接的身份验证(使用EAP或pre-shared密钥)前,没有执行服务器身
CVSS Information
N/A
Vulnerability Type
N/A