Impact
The vulnerability is a NULL pointer dereference in the eap-aka plugin of strongSwan versions 4.1.10 through 6.0.7. The flaw can cause the software to crash during authentication processing, resulting in a denial of service and potentially disrupting VPN connections for affected users. The weakness is categorized as CWE‑476.
Affected Systems
The affected product isSwan strongswan, and the version range impacted is 4.1.10 to 6.0.7 inclusive. No other vendors or products are listed in the data.
Risk and Exploitability
The CVSS score of 5.9 denotes moderate severity, and the EPSS score is not available, indicating no published data on exploitation frequency. The vulnerability is not listed in the CISA KEV catalog. The flaw is triggered when the eap-aka plugin processes authentication traffic, so the likely attack vector is remote, via an attacker who can send crafted EAP‑AKA messages during the VPN handshake. The exact exploitation conditions are not fully described in the source data, so the assessment assumes that the attacker can reach the authentication service.
OpenCVE Enrichment
Debian DSA
Ubuntu USN