strongswan
Security Risk Profile
48
/100
mediumSecurity Risk Score
Comprehensive risk assessment based on 44 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from June 30, 2004 to present
44
Total CVEs
23
Critical+High
0
Exploited
10
Unpatched
Threat Assessment
Avg CVSS
6.6
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
10
Critical/High
Risk Level
48/100
medium
Severity Distribution
Critical
5High
18Medium
18Low
2Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
2Age Distribution
Common Weaknesses (CWE)
1
Null Pointer Dereference
10
2
Buffer Overflow
8
3
Input Validation
4
4
Integer Overflow
3
5
Integer Underflow
2
Most Affected Products
1. strongSwan Strongswan672
2. Xelerance Openswan53
3. Canonical Ubuntu Linux37
4. Debian Debian Linux24
5. Fedoraproject Fedora13
Recent Vulnerabilities
See more →CVE-2026-25075
CVSS 8.7high
strongSwan 4.5.0 < 6.0.5 EAP-TTLS AVP Parsing Integer Underflow
3/23/2026
https://seclists.org/oss-sec/2026/q1/185
unknown
Default IV & other issues in aes-js & pyaes modules, & strongMan VPN manager
2/19/2026🔧 No Patch
CVE-2026-25998
CVSS 8.7EPSS 0%high
strongMan vulnerable to private credential recovery due to key and counter reuse
2/19/2026🔧 No Patch
CVE-2025-62291
CVSS 8.1high
1/16/2026🔧 No Patch
CVE-2025-8763
CVSS 6.3EPSS 0%medium
Ruijie EG306MG strongSwan strongswan.conf missing encryption
8/9/2025🔧 No Patch
CVE-2025-44647
CVSS 7.3high
7/21/2025🔧 No Patch
CVE-2022-4967
CVSS 7.7high
5/13/2024
CVE-2023-41913
CVSS 9.8critical
11/20/2023
CVE-2023-26463
CVSS 9.8critical
4/14/2023🔧 No Patch
CVE-2022-40617
CVSS 7.5high
10/31/2022🔧 No Patch
Monitor strongswan in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.