Authorization Bypass through Improper Certificate Validation
CVE-2022-4967
What is CVE-2022-4967?
A vulnerability exists in strongSwan versions 5.9.2 through 5.9.5 due to improper validation of certificates, resulting in authorization bypass. This issue allows clients to authenticate using any trusted certificate without the necessary enforcement of client identities being matched with those on the certificates. As a result, clients can claim any arbitrary IKE or EAP identity, which could lead to significant security risks, particularly when client identity is crucial for policy enforcement. A fix was released in strongSwan version 5.9.6 in August 2022.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
strongSwan Linux 5.9.2 < 5.9.6
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
