CVE-2022-4967 Details
Description
strongSwan versions 5.9.2 through 5.9.5 are affected by authorization bypass through improper validation of certificate with host mismatch (CWE-297). When certificates are used to authenticate clients in TLS-based EAP methods, the IKE or EAP identity supplied by a client is not enforced to be contained in the client's certificate. So clients can authenticate with any trusted certificate and claim an arbitrary IKE/EAP identity as their own. This is problematic if the identity is used to make policy decisions. A fix was released in strongSwan version 5.9.6 in August 2022 (e4b4aabc4996fc61c37deab7858d07bc4d220136).
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 17, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/strongswan/strongswan/commit/e4b4aabc4996fc61c37deab7858d07bc4d220136 | CVE | Patch |
| https://security.netapp.com/advisory/ntap-20240614-0006/ | CVE | Third Party Advisory |
| https://www.cve.org/CVERecord?id=CVE-2022-4967 | CVE | Third Party Advisory |
| https://www.strongswan.org/blog/2024/05/13/strongswan-vulnerability-(cve-2022-4967).html | CVE | MitigationVendor Advisory |
| https://github.com/strongswan/strongswan/commit/e4b4aabc4996fc61c37deab7858d07bc4d220136 | [email protected] | Patch |
| https://security.netapp.com/advisory/ntap-20240614-0006/ | [email protected] | Third Party Advisory |
| https://www.cve.org/CVERecord?id=CVE-2022-4967 | [email protected] | Third Party Advisory |
| https://www.strongswan.org/blog/2024/05/13/strongswan-vulnerability-(cve-2022-4967).html | [email protected] | MitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-Other | Weakness Not in a Standard CWE Category | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| strongswan strongswan | >= 5.9.2, < 5.9.6 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 6, 2025 | Reanalysis | [email protected] |
| Aug 22, 2025 | Initial Analysis | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| Jun 14, 2024 | CVE Modified | [email protected] |
| May 14, 2024 | New CVE Received | [email protected] |