Metrics
Affected Vendors & Products
Mon, 04 May 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 27 Mar 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 25 Mar 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 24 Mar 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Strongswan
Strongswan strongswan |
|
| Vendors & Products |
Strongswan
Strongswan strongswan |
Mon, 23 Mar 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | strongSwan EAP-TTLS AVP Parsing Integer Underflow | strongSwan 4.5.0 < 6.0.5 EAP-TTLS AVP Parsing Integer Underflow |
Mon, 23 Mar 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | strongSwan versions 4.5.0 prior to 6.0.5 contain an integer underflow vulnerability in the EAP-TTLS AVP parser that allows unauthenticated remote attackers to cause a denial of service by sending crafted AVP data with invalid length fields during IKEv2 authentication. Attackers can exploit the failure to validate AVP length fields before subtraction to trigger excessive memory allocation or NULL pointer dereference, crashing the charon IKE daemon. | |
| Title | strongSwan EAP-TTLS AVP Parsing Integer Underflow | |
| Weaknesses | CWE-191 CWE-476 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-03-23T18:33:10.952Z
Updated: 2026-05-04T18:10:36.898Z
Reserved: 2026-01-28T21:47:35.121Z
Link: CVE-2026-25075
Updated: 2026-03-27T19:17:30.660Z
Status : Deferred
Published: 2026-03-23T19:16:39.313
Modified: 2026-05-04T19:16:02.690
Link: CVE-2026-25075
No data.
ReportizFlow