Authorization Bypass through Improper Certificate Validation
CVE-2022-4967
7.7HIGH
What is CVE-2022-4967?
A vulnerability exists in strongSwan versions 5.9.2 through 5.9.5 due to improper validation of certificates, resulting in authorization bypass. This issue allows clients to authenticate using any trusted certificate without the necessary enforcement of client identities being matched with those on the certificates. As a result, clients can claim any arbitrary IKE or EAP identity, which could lead to significant security risks, particularly when client identity is crucial for policy enforcement. A fix was released in strongSwan version 5.9.6 in August 2022.
Affected Version(s)
strongSwan Linux 5.9.2 < 5.9.6
