High-Severity strongSwan Flaw Enables Remote VPN Gateway Crashes
ID: c0818433-cf19-514b-9fe1-9ee6c84a4ca3
STIX ID: report--c0818433-cf19-514b-9fe1-9ee6c84a4ca3
Feed Name: securityonline.info
High-severity vulnerability CVE-2026-25075 was disclosed in strongSwan's eap-ttls plugin (CVSSv4 8.7). A crafted EAP-TTLS AVP header with an invalid length can trigger an integer underflow that leads to large memory allocation attempts or a null-pointer dereference, enabling unauthenticated remote denial-of-service against VPN gateways; the issue affects all versions since 4.5.0 and is mitigated by applying the patch, disabling eap-ttls if unused, or restricting endpoint access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
