<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T17:17:26.612974+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-079</id>
    <title>certfr-2022-avi-079 — Une vulnérabilité a été découverte dans strongSwan. Elle permet à un
attaquant de provoquer un déni de service à distan…</title>
    <updated>2026-10-03T17:17:26.856303+00:00</updated>
    <content>certfr-2022-avi-079</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-079"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-33199</id>
    <title>EUVD-2026-33199</title>
    <updated>2026-10-03T17:17:26.856369+00:00</updated>
    <content>EUVD-2026-33199</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-33199"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-45079</id>
    <title>fkie_cve-2021-45079</title>
    <updated>2026-10-03T17:17:26.856386+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticating the client and (in the case of EAP methods with mutual authentication and EAP-only authentication for IKEv2) even without server authentication.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-45079"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8x8f-8g3r-h75g</id>
    <title>GHSA-8x8f-8g3r-h75g</title>
    <updated>2026-10-03T17:17:26.856422+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticating the client and (in the case of EAP methods with mutual authentication and EAP-only authentication for IKEv2) even without server authentication.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8x8f-8g3r-h75g"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-45079</id>
    <title>gsd-2021-45079</title>
    <updated>2026-10-03T17:17:26.856438+00:00</updated>
    <content>gsd-2021-45079</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-45079"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2021-45079</id>
    <title>msrc_CVE-2021-45079 — In strongSwan before 5.9.5 a malicious responder can send an EAP-Success message too early without actually authenticat…</title>
    <updated>2026-10-03T17:17:26.856450+00:00</updated>
    <content>msrc_CVE-2021-45079</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2021-45079"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2022-1525</id>
    <title>OESA-2022-1525 — strongswan security update</title>
    <updated>2026-10-03T17:17:26.856467+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: strongswan, openEuler:20.03-LTS-SP2: strongswan, openEuler:20.03-LTS-SP3: strongswan</p>
<p>The strongSwan IPsec implementation supports both the IKEv1 and IKEv2 key exchange protocols in conjunction with the native NETKEY IPsec stack of the Linux kernel.

Security Fix(es):

In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticating the client and (in the case of EAP methods with mutual authentication and EAP-only authentication for IKEv2) even without server authentication.(CVE-2021-45079)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2022-1525"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2022:0492-1</id>
    <title>openSUSE-SU-2022:0492-1 — Security update for strongswan</title>
    <updated>2026-10-03T17:17:26.856495+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for strongswan</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2022:0492-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2022:0202-1</id>
    <title>SUSE-SU-2022:0202-1 — Security update for strongswan</title>
    <updated>2026-10-03T17:17:26.856512+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for strongswan</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2022:0202-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-45079</id>
    <title>UBUNTU-CVE-2021-45079</title>
    <updated>2026-10-03T17:17:26.856527+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: strongswan, Ubuntu:Pro:16.04:LTS: strongswan, Ubuntu:Pro:FIPS:16.04:LTS: strongswan, Ubuntu:18.04:LTS: strongswan, Ubuntu:Pro:FIPS-updates:18.04:LTS: strongswan, Ubuntu:Pro:FIPS:18.04:LTS: strongswan, Ubuntu:20.04:LTS: strongswan, Ubuntu:Pro:FIPS-updates:20.04:LTS: strongswan, Ubuntu:Pro:FIPS:20.04:LTS: strongswan, Ubuntu:22.04:LTS: strongswan</p>
<p>In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticating the client and (in the case of EAP methods with mutual authentication and EAP-only authentication for IKEv2) even without server authentication.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-45079"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2022-010</id>
    <title>VDE-2022-010 — PHOENIX CONTACT: Multiple Linux component vulnerabilities fixed in latest AXC F x152 LTS release</title>
    <updated>2026-10-03T17:17:26.856564+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>PLCnext Control AXC F x152 is certified according to IEC 62443-4-1 and IEC 62443-4-2.
This certification requires that all third-party components used in the firmware are regularly checked for known vulnerabilities.</p>
<p>Firmware components in version 2021.06 had already been updated. For the 2022.0 LTS version more firmware components have been updated implicitly fixing the vulnerabilities listed. The vulnerabilities listed above have not been individually verified in terms of actual impact and/or limitations in combination with the affected products listed. The current LTS release 2022.0 LTS contains updates of integrated third-party libraries, SDKs and other third-party software to address these issues nevertheless.</p>
<p>UPDATE A (April 4th, 2022): Added RFC 4072 (Art. No. 1051328) and fixed affected version of AXC F 3152</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2022-010"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1023</id>
    <title>WID-SEC-W-2024-1023 — strongSwan: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
    <updated>2026-10-03T17:17:26.856690+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in strongSwan ausnutzen, um Sicherheitsvorkehrungen zu umgehen und einen Denial of Service Zustand herzustellen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1023"/>
  </entry>
</feed>
