The server implementation of the EAP-MSCHAPv2 protocol in the eap-mschapv2 plugin in strongSwan 4.2.12 through 5.x before 5.3.4 does not properly validate local state, which allows remote attackers to bypass authentication via an empty Success message in response to an initial Challenge message.
{
"binaries": [
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "libstrongswan"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-ike"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-ikev1"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-ikev2"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-nm"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-plugin-af-alg"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-plugin-agent"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-plugin-attr-sql"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-plugin-certexpire"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-plugin-coupling"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-plugin-curl"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-plugin-dhcp"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-plugin-dnscert"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-plugin-dnskey"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-plugin-duplicheck"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-plugin-eap-aka"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-plugin-eap-aka-3gpp2"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-plugin-eap-dynamic"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-plugin-eap-gtc"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-plugin-eap-md5"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-plugin-eap-mschapv2"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-plugin-eap-peap"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-plugin-eap-radius"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-plugin-eap-sim"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-plugin-eap-sim-file"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-plugin-eap-sim-pcsc"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-plugin-eap-simaka-pseudonym"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-plugin-eap-simaka-reauth"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-plugin-eap-simaka-sql"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-plugin-eap-tls"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-plugin-eap-tnc"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-plugin-eap-ttls"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-plugin-error-notify"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-plugin-farp"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-plugin-fips-prf"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-plugin-gcrypt"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-plugin-gmp"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-plugin-ipseckey"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-plugin-kernel-libipsec"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-plugin-ldap"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-plugin-led"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-plugin-load-tester"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-plugin-lookip"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-plugin-mysql"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-plugin-ntru"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-plugin-openssl"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-plugin-pgp"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-plugin-pkcs11"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-plugin-pubkey"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-plugin-radattr"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-plugin-soup"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-plugin-sql"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-plugin-sqlite"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-plugin-sshkey"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-plugin-systime-fix"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-plugin-unbound"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-plugin-unity"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-plugin-whitelist"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-plugin-xauth-eap"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-plugin-xauth-generic"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-plugin-xauth-noauth"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-plugin-xauth-pam"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-pt-tls-client"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-starter"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-tnc-base"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-tnc-client"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-tnc-ifmap"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-tnc-pdp"
},
{
"binary_version": "5.1.2-0ubuntu2.4",
"binary_name": "strongswan-tnc-server"
}
],
"availability": "No subscription required"
}
{
"binaries": [
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "libstrongswan"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-ike"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-ikev1"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-ikev2"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-nm"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-plugin-af-alg"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-plugin-agent"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-plugin-attr-sql"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-plugin-certexpire"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-plugin-coupling"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-plugin-curl"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-plugin-dhcp"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-plugin-dnscert"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-plugin-dnskey"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-plugin-duplicheck"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-plugin-eap-aka"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-plugin-eap-aka-3gpp2"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-plugin-eap-dynamic"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-plugin-eap-gtc"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-plugin-eap-md5"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-plugin-eap-mschapv2"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-plugin-eap-peap"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-plugin-eap-radius"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-plugin-eap-sim"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-plugin-eap-sim-file"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-plugin-eap-sim-pcsc"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-plugin-eap-simaka-pseudonym"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-plugin-eap-simaka-reauth"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-plugin-eap-simaka-sql"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-plugin-eap-tls"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-plugin-eap-tnc"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-plugin-eap-ttls"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-plugin-error-notify"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-plugin-farp"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-plugin-fips-prf"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-plugin-gcrypt"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-plugin-gmp"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-plugin-ipseckey"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-plugin-kernel-libipsec"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-plugin-ldap"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-plugin-led"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-plugin-load-tester"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-plugin-lookip"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-plugin-mysql"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-plugin-ntru"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-plugin-openssl"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-plugin-pgp"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-plugin-pkcs11"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-plugin-pubkey"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-plugin-radattr"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-plugin-soup"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-plugin-sql"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-plugin-sqlite"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-plugin-sshkey"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-plugin-systime-fix"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-plugin-unbound"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-plugin-unity"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-plugin-whitelist"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-plugin-xauth-eap"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-plugin-xauth-generic"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-plugin-xauth-noauth"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-plugin-xauth-pam"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-pt-tls-client"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-starter"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-tnc-base"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-tnc-client"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-tnc-ifmap"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-tnc-pdp"
},
{
"binary_version": "5.1.2-0ubuntu7",
"binary_name": "strongswan-tnc-server"
}
],
"availability": "No subscription required"
}