CVE-2014-2338: Strongswan
Medium severity, CVSS 6.4. EPSS: 2.4% chance of exploitation in the next 30 days.
IKEv2 in strongSwan 4.0.7 before 5.1.3 allows remote attackers to bypass authentication by rekeying an IKE_SA during (1) initiation or (2) re-authentication, which triggers the IKE_SA state to be set to established.
Affected products
- Strongswan Strongswan: version 4.0.7 only; version 4.1.0 only; version 4.1.1 only; version 4.1.2 only; version 4.1.3 only; version 4.1.4 only; …
Published 2014-04-16. Last modified 2026-06-17.