Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2847▼ 151 respecto a la semana anterior
Críticas / altas1373▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 257 respecto a la semana anterior
53 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.3) | 0.36% | — | Strongswan | 11/9/2026 | 16/9/2026 | libcharon in strongSwan 5.9.7 through 6.0.7 mishandles behavioral workflow in the IKEv2 state machine. Because CREATE_CHILD_SA requests are mishandled, there can be an authentication bypass. | |
| Analizada | Alta (7.1) | 0.32% | — | Strongswan | 11/9/2026 | 14/9/2026 | strongSwan 4.5.0 through 6.0.7 has Incorrect Access Control in the eap-ttls and eap-peap plugins because there can be a missing or mismatched inner EAP identity. | |
| Analizada | Alta (7.5) | 0.43% | — | Strongswan | 11/9/2026 | 14/9/2026 | libcharon in strongSwan 6.0.0 through 6.0.7 has a use-after-free in IKEv2 rekeying collision handling. | |
| Analizada | Alta (7.5) | 0.32% | — | Strongswan | 11/9/2026 | 14/9/2026 | strongSwan 5.1.3 through 6.0.7 has an infinite loop in the x509 plugin's attribute certificate parser for ietfAttrSyntax. | |
| Analizada | Baja (3.7) | 0.23% | — | Strongswan | 11/9/2026 | 14/9/2026 | strongSwan 4.2.0 through 6.0.7 has a missing release of memory after its effective lifetime in the x509 plugin's attribute certificate parser. | |
| Analizada | Alta (7.5) | 0.32% | — | Strongswan | 11/9/2026 | 15/9/2026 | strongSwan 4.2.0 through 6.0.7 has a NULL pointer dereference in the x509 plugin's attribute certificate parser. | |
| Analizada | Media (5.9) | 0.41% | — | Strongswan | 11/9/2026 | 14/9/2026 | strongSwan 4.6.2 through 6.0.7 has an infinite loop in PKCS#5 decryption. | |
| Analizada | Baja (3.7) | 0.35% | — | Strongswan | 11/9/2026 | 14/9/2026 | libcharon in strongSwan 4.1.2 through 6.0.7 has a missing release of memory after its effective lifetime in the IKE message parser. | |
| Analizada | Media (5.9) | 0.41% | — | Strongswan | 11/9/2026 | 14/9/2026 | strongSwan 4.1.10 through 6.0.7 allows a NULL pointer dereference in the eap-aka plugin. | |
| Analizada | Baja (3.7) | 0.19% | — | Strongswan | 11/9/2026 | 14/9/2026 | strongSwan 5.0.2 through 6.0.7 allows PKCS#7 certificate enumeration in the openssl plugin that leads to a lack of release of memory after its effective lifetime. | |
| Analizada | Media (5.9) | 0.41% | — | Strongswan | 11/9/2026 | 15/9/2026 | strongSwan 5.0.2 through 6.0.7 has an Expired Pointer Dereference in PKCS#7 parsing in the openssl plugin. | |
| Aplazada | Alta (7.5) | 0.42% | — | StrongswanAI | 22/8/2026 | 9/9/2026 | In strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-Identities that result in an empty but non-NULL encoding are not correctly cloned and trigger a double-free once the duplicates are destroyed. | |
| Aplazada | Alta (8.7) | 1.0% | — | StrongswanAI | 23/3/2026 | 14/7/2026 | strongSwan versions 4.5.0 prior to 6.0.5 contain an integer underflow vulnerability in the EAP-TTLS AVP parser that allows unauthenticated remote attackers to cause a denial of service by sending crafted AVP data with invalid length fields during IKEv2 authentication. Attackers can exploit the failure to validate AVP… | |
| Analizada | Alta (8.7) | 0.27% | — | Strongswan Strongman | 19/2/2026 | 17/6/2026 | strongMan is a management interface for strongSwan, an OpenSource IPsec-based VPN. When storing credentials in the database (private keys, EAP secrets), strongMan encrypts the corresponding database fields. So far it used AES in CTR mode with a global database key. Together with an initialization vector (IV), a key… | |
| Aplazada | Alta (8.1) | 1.00% | — | StrongswanAI | 16/1/2026 | 17/6/2026 | In the eap-mschapv2 plugin (client-side) in strongSwan before 6.0.3, a malicious EAP-MSCHAPv2 server can send a crafted message of size 6 through 8, and cause an integer underflow that potentially results in a heap-based buffer overflow. | |
| Aplazada | Media (6.3) | 0.15% | — | Ruijie Eg306mgAIStrongswanAI | 9/8/2025 | 17/6/2026 | A vulnerability was found in Ruijie EG306MG 3.0(1)B11P309. It has been rated as problematic. This issue affects some unknown processing of the file /etc/strongswan.conf of the component strongSwan. The manipulation of the argument i_dont_care_about_security_and_use_aggressive_mode_psk leads to missing encryption of… | |
| Analizada | Media (6.5) | 0.47% | — | Strongswan | 14/5/2024 | 17/6/2026 | strongSwan versions 5.9.2 through 5.9.5 are affected by authorization bypass through improper validation of certificate with host mismatch (CWE-297). When certificates are used to authenticate clients in TLS-based EAP methods, the IKE or EAP identity supplied by a client is not enforced to be contained in the client's… | |
| Modificada | Crítica (9.8) | 2.3% | — | Strongswan | 7/12/2023 | 17/6/2026 | strongSwan before 5.9.12 has a buffer overflow and possible unauthenticated remote code execution via a DH public value that exceeds the internal buffer in charon-tkm's DH proxy. The earliest affected version is 5.3.0. An attack can occur via a crafted IKE_SA_INIT message. | |
| Modificada | Crítica (9.8) | 2.3% | — | Strongswan | 15/4/2023 | 17/6/2026 | strongSwan 5.9.8 and 5.9.9 potentially allows remote code execution because it uses a variable named "public" for two different purposes within the same function. There is initially incorrect access control, later followed by an expired pointer dereference. One attack vector is sending an untrusted client certificate… | |
| Modificada | Alta (7.5) | 1.8% | — | StrongswanCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora+1 | 31/10/2022 | 17/6/2026 | strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a crafted end-entity (and intermediate CA) certificate that contains a CRL/OCSP URL that points to a server (under the attacker's control) that doesn't properly respond but (for example) just does nothing… | |
| Modificada | Crítica (9.1) | 2.8% | — | StrongswanDebian LinuxFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora+1 | 31/1/2022 | 17/6/2026 | In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticating the client and (in the case of EAP methods with mutual authentication and EAP-only authentication for IKEv2) even without server authentication. | |
| Modificada | Alta (7.5) | 5.3% | — | StrongswanDebian LinuxFedoraproject FedoraSiemens Sinema Remote Connect Server+21 | 18/10/2021 | 17/6/2026 | The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to fill the cache and later trigger the replacement of cache entries. The code attempts to select a less-often-used cache entry by means of a random number generator, but… | |
| Modificada | Alta (7.5) | 6.7% | — | StrongswanDebian LinuxFedoraproject FedoraSiemens 6gk6108-4am00-2ba2 Firmware+16 | 18/10/2021 | 17/6/2026 | The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example, this can be triggered by an unrelated self-signed CA certificate sent by an initiator. Remote code execution cannot occur. | |
| Modificada | Baja (3.1) | 0.50% | — | LibreswanStrongswanXelerance OpenswanFedoraproject Fedora+1 | 12/6/2019 | 17/6/2026 | The Libreswan Project has found a vulnerability in the processing of IKEv1 informational exchange packets which are encrypted and integrity protected using the established IKE SA encryption and integrity keys, but as a receiver, the integrity check value was not verified. This issue affects versions before 3.29. | |
| Modificada | Alta (7.5) | 3.5% | — | StrongswanDebian LinuxCanonical Ubuntu Linux | 3/10/2018 | 17/6/2026 | The gmp plugin in strongSwan before 5.7.1 has a Buffer Overflow via a crafted certificate. |