Impact
A flaw in the eap-ttls and eap-peap plugins of strongSwan allows an attacker to bypass inner EAP identity checks, potentially leading to unauthorized access to protected resources. This weakness is classified under CWE-863, which denotes Incorrect Authorization. The vulnerability does not directly disclose or modify data, but it removes a critical gate that validates the identity presented during the TLS inner EAP phase, thereby enabling an attacker to impersonate a legitimate client or server without detection. No additional disclosures or evidence of compromise were reported in the advisory, so the impact is limited to successful exploitation of the authentication process.
Affected Systems
strongSwan VPN software versions 4.5.0 through 6.0.7 are affected. The issue is present in the eap-ttls and eap-peap authentication modules, which are commonly used in enterprise VPN deployments. The most recent release notes at https://github.com/strongswan/strongswan/releases/tag/6.1.0 indicate that the vulnerability has been addressed in version 6.1.0, but no specific notes are provided to confirm the fix. Administrators should check that their deployment falls within the vulnerable range and whether any custom modules or patches are in use.
Risk and Exploitability
The CVSS score of 7.1 signifies a high severity impact, but without an EPSS score the likelihood of immediate exploitation remains unknown. The vulnerability is not listed in CISA’s KEV catalog, implying no known widespread exploitation. The attack vector is inferred to be remote, as the affected plugin is part of the IPsec VPN service exposed to network traffic. Successful exploitation would primarily allow an attacker to authenticate incorrectly and gain unauthorized access, potentially escalating privileges if additional vulnerabilities are present. Administrators should treat this as a high priority remediation item due to the serious nature of unauthorized access.
OpenCVE Enrichment
Debian DSA
Ubuntu USN