Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-25075

32
FAUCET Score

CVE-2026-25075 is an integer underflow vulnerability affecting strongSwan versions 4.5.0 prior to 6.0.5, specifically within the EAP-TTLS AVP parser due to insufficient validation of AVP length fields. This high-severity (CVSS 7.5) flaw allows unauthenticated remote attackers to cause a denial of service by sending crafted AVP data during IKEv2 authentication, potentially leading to excessive memory allocation or NULL pointer dereference and crashing the charon IKE daemon. There is currently no evidence of active exploitation, nor are public exploit codes available on platforms like Metasploit or ExploitDB, though the vulnerability has received community discussion and vendor attention, including security updates from SUSE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.5.0, < 6.0.5CPE match
cpe:2.3:a:strongswan:strongswan:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

8.7HIGH

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
NONE
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
1.01%
Probability of exploitation in next 30 days
EPSS Percentile
59.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0101 is in the 36th percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

microsoftpatch availablevia msrc
Product: 20896-17084Fixed in: 5.9.14-9
microsoftpatch availablevia msrc
Product: azl3 strongswan 5.9.14-8 on Azure Linux 3.0Fixed in: 5.9.14-9
ubuntupatch availablevia ubuntu_usn
Product: strongswan (jammy)Fixed in: 5.9.5-2ubuntu2.5
ubuntupatch availablevia ubuntu_usn
Product: strongswan (noble)Fixed in: 5.9.13-2ubuntu4.24.04.2
ubuntupatch availablevia ubuntu_usn
Product: strongswan (questing)Fixed in: 6.0.1-6ubuntu4.2

Vendor Advisories (2)

ubuntuUSN-8117-1

strongSwan vulnerability

Mar 23, 2026
microsoft2026-Mar/CVE-2026-25075Important

strongSwan 4.5.0 < 6.0.5 EAP-TTLS AVP Parsing Integer Underflow

Mar 10, 2026

References

lists.debian.org / debian-lts-announce/2026/03/msg00016.html
strongswan.org / blog/2026/03/23/strongswan-6.0.5-released.html
strongswan.org / blog/2026/03/23/strongswan-vulnerability-(cve-2026-25075).html
vulncheck.com / advisories/strongswan-eap-ttls-avp-parsing-integer-underflow
y637f9qq2x.com / posts/cve-2026-25075