CVE-2025-62291

8.1

strongSwan · strongSwan

A heap-based buffer overflow vulnerability in the strongSwan eap-mschapv2 plugin allows a malicious server to trigger an integer underflow via crafted messages.

Executive summary

A critical heap-based buffer overflow vulnerability in the strongSwan eap-mschapv2 plugin poses a significant risk of remote code execution or system crash by an unauthenticated attacker.

Vulnerability

The vulnerability stems from an integer underflow (CWE-191) in the client-side eap-mschapv2 plugin, where a malicious server sends a crafted message of specific size to trigger a heap-based buffer overflow. This attack can be performed by an unauthenticated remote server interacting with a vulnerable strongSwan client.

Business impact

Successful exploitation of this vulnerability can lead to a heap-based buffer overflow, potentially allowing for remote code execution or service disruption. With a CVSS score of 8.1, this represents a high-severity threat that could compromise the confidentiality, integrity, and availability of VPN client systems. Organizations relying on strongSwan for secure connectivity are at risk of unauthorized system access if their clients connect to malicious or compromised EAP-MSCHAPv2 servers.

Remediation

Immediate Action: Upgrade all instances of the strongSwan client to version 6.0.3 or later to incorporate the vendor-provided fix.

Proactive Monitoring: Monitor VPN connection logs for unusual traffic patterns or unexpected client service crashes that may indicate an attempted exploitation of the eap-mschapv2 plugin.

Compensating Controls: Ensure that strongSwan clients only connect to trusted, authenticated VPN gateways and restrict network traffic to known-good infrastructure to reduce the attack surface.

Exploitation status

Public Exploit Available: No (exploit_available: unknown)

Analyst recommendation

Given the high CVSS score and the nature of the vulnerability residing in a security-critical component like the VPN client, immediate patching is required. Administrators should verify the current version of strongSwan across all endpoints and prioritize the update to version 6.0.3 to eliminate the integer underflow flaw and protect against potential remote exploitation.

More strongSwan CVEs

Sources