Impact
The vulnerability is an infinite loop triggered during PKCS#5 decryption in strongSwan versions 4.6.2 through 6.0.7, leading to a denial of service by consuming processing resources until the system becomes unresponsive. This weakness represents a classic improper loop control flaw (CWE‑835).
Affected Systems
StrongSwan, as released by the strongSwan project, is affected for versions 4.6.2 through 6.0.7. No other vendors or products are listed in the impact data.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity. The EPSS score is not available and the vulnerability is not currently listed in the CISA KEV catalog. Based on the description it is inferred that the attack vector is remote, leveraging network traffic that is processed by the PKCS#5 decryption routine during IPsec negotiations. An attacker who can supply malformed encrypted payloads could potentially trigger the infinite loop, exhausting CPU resources and causing service disruption.
OpenCVE Enrichment
Debian DSA
Ubuntu USN