EAP Authentication Vulnerability in strongSwan by strongSwan
CVE-2021-45079
9.1CRITICAL
What is CVE-2021-45079?
In strongSwan versions prior to 5.9.5, a security flaw allows a malicious responder to send an EAP-Success message prematurely. This can occur without proper client authentication and, in cases involving mutual authentication or EAP-only authentication for IKEv2, even without server authentication. This critical weakness could enable unauthorized access to network resources, posing significant risks to the integrity and confidentiality of secure communications.
