Integer Underflow Vulnerability in strongSwan's EAP-MSCHAPv2 Plugin
CVE-2025-62291
8.1HIGH
What is CVE-2025-62291?
The eap-mschapv2 plugin in strongSwan prior to version 6.0.3 is susceptible to an integer underflow vulnerability. This occurs when a malicious EAP-MSCHAPv2 server sends a specifically crafted message of size between 6 and 8 bytes. The flaw may result in a heap-based buffer overflow, potentially allowing unauthorized access or manipulation of sensitive data. It is crucial for users and administrators of strongSwan to upgrade to the latest version to mitigate this risk.
Affected Version(s)
strongSwan 4.2.12 < 6.0.3
