CVE-2015-4171: Infoleak
strongSwan 4.3.0 through 5.x before 5.3.2 and strongSwan VPN Client before 1.4.6, when using EAP or pre-shared keys for authenticating an IKEv2 connection, does not enforce server authentication restrictions until the entire authentication process is complete, which allows remote servers to obtain credentials by using a valid certificate and then reading the responses.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4171?
CVE-2015-4171 has a medium severity rating due to its potential to allow remote servers to bypass authentication restrictions.
How do I fix CVE-2015-4171?
To fix CVE-2015-4171, update to strongSwan versions 5.3.2 or later and strongSwan VPN Client 1.4.6 or later.
Which versions are affected by CVE-2015-4171?
CVE-2015-4171 affects strongSwan versions 4.3.0 to 5.x before 5.3.2 and strongSwan VPN Client versions before 1.4.6.
What is the primary impact of CVE-2015-4171?
The primary impact of CVE-2015-4171 is the inability to enforce server authentication restrictions during the IKEv2 authentication process.
Is CVE-2015-4171 exploitable in all configurations?
CVE-2015-4171 is specifically exploitable when using EAP or pre-shared keys for IKEv2 connection authentication.