Impact
libcharon in strongSwan versions 5.9.7 through 6.0.7 mishandles the IKEv2 state machine, specifically the CREATE_CHILD_SA request handling. This mismanagement permits an attacker to bypass authentication checks, effectively allowing unauthorized access to protected services or resources. The underlying weakness maps to CWE-841, which denotes mismanagement of platform or system resources that can lead to security problems.
Affected Systems
The affected product is strongSwan, a VPN IPsec implementation. Versions from 5.9.7 up to and including 6.0.7 are vulnerable. The vulnerability stems from the libcharon component, which handles IKEv2 negotiations. Systems running any of these versions in a networked environment, especially those configured to accept IKEv2 connections, are impacted.
Risk and Exploitability
The CVSS score of 5.6 indicates a medium severity vulnerability. No EPSS score is currently available, and the issue is not listed in the CISA KEV catalog, suggesting limited known exploitation. The likely attack vector is the network: an attacker who can send crafted CREATE_CHILD_SA messages in an IKEv2 exchange can trigger the misbehavior. Because the flaw allows bypassing authentication, it can enable subsequent unauthorized actions; however, exploitability depends on network access and the configuration of the strongSwan instance.
OpenCVE Enrichment
Debian DSA
Ubuntu USN