Buffer Overflow Vulnerability in strongSwan VPN Software
CVE-2023-41913
9.8CRITICAL
What is CVE-2023-41913?
A buffer overflow vulnerability exists in the strongSwan VPN software, specifically impacting versions prior to 5.9.12. This flaw allows the possibility of unauthenticated remote code execution through a manipulated Diffie-Hellman (DH) public value that exceeds the buffer limit in charon-tkm's DH proxy. Exploitation occurs via a specially crafted IKE_SA_INIT message, potentially enabling malicious actors to execute arbitrary code in the context of the application.
