CVE-2015-8023: Input Validation
The server implementation of the EAP-MSCHAPv2 protocol in the eap-mschapv2 plugin in strongSwan 4.2.12 through 5.x before 5.3.4 does not properly validate local state, which allows remote attackers to bypass authentication via an empty Success message in response to an initial Challenge message.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8023?
CVE-2015-8023 is classified as a medium severity vulnerability due to its ability to allow authentication bypass.
How do I fix CVE-2015-8023?
To fix CVE-2015-8023, update strongSwan to version 5.3.4 or later.
What versions of strongSwan are affected by CVE-2015-8023?
CVE-2015-8023 affects strongSwan versions from 4.2.12 up to, but not including, 5.3.4.
Which operating systems are impacted by CVE-2015-8023?
CVE-2015-8023 affects Ubuntu Linux versions 14.04, 15.04, and 15.10, as well as multiple versions of strongSwan.
What does CVE-2015-8023 exploit in the strongSwan implementation?
CVE-2015-8023 exploits improper validation of local state in the EAP-MSCHAPv2 protocol, allowing remote attackers to bypass authentication.