<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 16:06:58 +0000</lastBuildDate>
    <item>
      <title>certfr-2022-avi-079 — Une vulnérabilité a été découverte dans strongSwan. Elle permet à un
attaquant de provoquer un déni de service à distan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-079</link>
      <description>certfr-2022-avi-079</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-079</guid>
    </item>
    <item>
      <title>EUVD-2026-33199</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-33199</link>
      <description>EUVD-2026-33199</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-33199</guid>
    </item>
    <item>
      <title>fkie_cve-2021-45079</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-45079</link>
      <description>&lt;p&gt;In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticating the client and (in the case of EAP methods with mutual authentication and EAP-only authentication for IKEv2) even without server authentication.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticating the client and (in the case of EAP methods with mutual authentication and EAP-only authentication for IKEv2) even without server authentication.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-45079</guid>
    </item>
    <item>
      <title>GHSA-8x8f-8g3r-h75g</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8x8f-8g3r-h75g</link>
      <description>&lt;p&gt;In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticating the client and (in the case of EAP methods with mutual authentication and EAP-only authentication for IKEv2) even without server authentication.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticating the client and (in the case of EAP methods with mutual authentication and EAP-only authentication for IKEv2) even without server authentication.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8x8f-8g3r-h75g</guid>
    </item>
    <item>
      <title>gsd-2021-45079</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-45079</link>
      <description>gsd-2021-45079</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-45079</guid>
    </item>
    <item>
      <title>msrc_CVE-2021-45079 — In strongSwan before 5.9.5 a malicious responder can send an EAP-Success message too early without actually authenticat…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2021-45079</link>
      <description>msrc_CVE-2021-45079</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2021-45079</guid>
    </item>
    <item>
      <title>OESA-2022-1525 — strongswan security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2022-1525</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: strongswan, openEuler:20.03-LTS-SP2: strongswan, openEuler:20.03-LTS-SP3: strongswan&lt;/p&gt;
&lt;p&gt;The strongSwan IPsec implementation supports both the IKEv1 and IKEv2 key exchange protocols in conjunction with the native NETKEY IPsec stack of the Linux kernel.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticating the client and (in the case of EAP methods with mutual authentication and EAP-only authentication for IKEv2) even without server authentication.(CVE-2021-45079)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: strongswan, openEuler:20.03-LTS-SP2: strongswan, openEuler:20.03-LTS-SP3: strongswan&lt;/p&gt;
&lt;p&gt;The strongSwan IPsec implementation supports both the IKEv1 and IKEv2 key exchange protocols in conjunction with the native NETKEY IPsec stack of the Linux kernel.&#13;
&#13;
Security Fix(es):&#13;
&#13;
In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticating the client and (in the case of EAP methods with mutual authentication and EAP-only authentication for IKEv2) even without server authentication.(CVE-2021-45079)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2022-1525</guid>
    </item>
    <item>
      <title>openSUSE-SU-2022:0492-1 — Security update for strongswan</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2022:0492-1</link>
      <description>&lt;p&gt;Security update for strongswan&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for strongswan&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2022:0492-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2022:0202-1 — Security update for strongswan</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2022:0202-1</link>
      <description>&lt;p&gt;Security update for strongswan&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for strongswan&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2022:0202-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-45079</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-45079</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: strongswan, Ubuntu:Pro:16.04:LTS: strongswan, Ubuntu:Pro:FIPS:16.04:LTS: strongswan, Ubuntu:18.04:LTS: strongswan, Ubuntu:Pro:FIPS-updates:18.04:LTS: strongswan, Ubuntu:Pro:FIPS:18.04:LTS: strongswan, Ubuntu:20.04:LTS: strongswan, Ubuntu:Pro:FIPS-updates:20.04:LTS: strongswan, Ubuntu:Pro:FIPS:20.04:LTS: strongswan, Ubuntu:22.04:LTS: strongswan&lt;/p&gt;
&lt;p&gt;In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticating the client and (in the case of EAP methods with mutual authentication and EAP-only authentication for IKEv2) even without server authentication.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: strongswan, Ubuntu:Pro:16.04:LTS: strongswan, Ubuntu:Pro:FIPS:16.04:LTS: strongswan, Ubuntu:18.04:LTS: strongswan, Ubuntu:Pro:FIPS-updates:18.04:LTS: strongswan, Ubuntu:Pro:FIPS:18.04:LTS: strongswan, Ubuntu:20.04:LTS: strongswan, Ubuntu:Pro:FIPS-updates:20.04:LTS: strongswan, Ubuntu:Pro:FIPS:20.04:LTS: strongswan, Ubuntu:22.04:LTS: strongswan&lt;/p&gt;
&lt;p&gt;In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticating the client and (in the case of EAP methods with mutual authentication and EAP-only authentication for IKEv2) even without server authentication.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-45079</guid>
    </item>
    <item>
      <title>VDE-2022-010 — PHOENIX CONTACT: Multiple Linux component vulnerabilities fixed in latest AXC F x152 LTS release</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2022-010</link>
      <description>&lt;p&gt;PLCnext Control AXC F x152 is certified according to IEC 62443-4-1 and IEC 62443-4-2.
This certification requires that all third-party components used in the firmware are regularly checked for known vulnerabilities.&lt;/p&gt;
&lt;p&gt;Firmware components in version 2021.06 had already been updated. For the 2022.0 LTS version more firmware components have been updated implicitly fixing the vulnerabilities listed. The vulnerabilities listed above have not been individually verified in terms of actual impact and/or limitations in combination with the affected products listed. The current LTS release 2022.0 LTS contains updates of integrated third-party libraries, SDKs and other third-party software to address these issues nevertheless.&lt;/p&gt;
&lt;p&gt;UPDATE A (April 4th, 2022): Added RFC 4072 (Art. No. 1051328) and fixed affected version of AXC F 3152&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;PLCnext Control AXC F x152 is certified according to IEC 62443-4-1 and IEC 62443-4-2.
This certification requires that all third-party components used in the firmware are regularly checked for known vulnerabilities.&lt;/p&gt;
&lt;p&gt;Firmware components in version 2021.06 had already been updated. For the 2022.0 LTS version more firmware components have been updated implicitly fixing the vulnerabilities listed. The vulnerabilities listed above have not been individually verified in terms of actual impact and/or limitations in combination with the affected products listed. The current LTS release 2022.0 LTS contains updates of integrated third-party libraries, SDKs and other third-party software to address these issues nevertheless.&lt;/p&gt;
&lt;p&gt;UPDATE A (April 4th, 2022): Added RFC 4072 (Art. No. 1051328) and fixed affected version of AXC F 3152&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2022-010</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-1023 — strongSwan: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1023</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in strongSwan ausnutzen, um Sicherheitsvorkehrungen zu umgehen und einen Denial of Service Zustand herzustellen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in strongSwan ausnutzen, um Sicherheitsvorkehrungen zu umgehen und einen Denial of Service Zustand herzustellen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1023</guid>
    </item>
  </channel>
</rss>
