logo

High-Severity strongSwan Flaw Enables Remote VPN Gateway Crashes

ID: c0818433-cf19-514b-9fe1-9ee6c84a4ca3

STIX ID: report--c0818433-cf19-514b-9fe1-9ee6c84a4ca3

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-03-26

Date Updated: 2026-04-23

Author: Ddos

...
...

High-severity vulnerability CVE-2026-25075 was disclosed in strongSwan's eap-ttls plugin (CVSSv4 8.7). A crafted EAP-TTLS AVP header with an invalid length can trigger an integer underflow that leads to large memory allocation attempts or a null-pointer dereference, enabling unauthenticated remote denial-of-service against VPN gateways; the issue affects all versions since 4.5.0 and is mitigated by applying the patch, disabling eap-ttls if unused, or restricting endpoint access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.