Impact
The vulnerability is a NULL pointer dereference in the X.509 attribute certificate parser of strongSwan. When an attacker supplies a crafted attribute certificate, to crash or become unresponsive. This failure can lead to a denial of service.
Affected Systems
strongSwan, versions 4.2.0 through 6.0.7, which can be obtained from the official release page.
Risk and Exploitability
The CVSS score of 7.5 indicates a moderate to high severity. EPSS data is not available and it is not listed in the CISA KEV catalog, suggesting that no confirmed exploits are widespread. The likely attack vector is an attacker sending a malicious certificate over the network, which, if the server is configured to accept attribute certificates, could trigger the crash.
OpenCVE Enrichment
Debian DSA
Ubuntu USN