CVE-2015-4171: Canonical Ubuntu Linux

Low severity, CVSS 2.6. EPSS: 2% chance of exploitation in the next 30 days.

strongSwan 4.3.0 through 5.x before 5.3.2 and strongSwan VPN Client before 1.4.6, when using EAP or pre-shared keys for authenticating an IKEv2 connection, does not enforce server authentication restrictions until the entire authentication process is complete, which allows remote servers to obtain credentials by using a valid certificate and then reading the responses.

Affected products

  • Canonical Ubuntu Linux: version 14.04 only; version 14.10 only; version 15.04 only
  • Debian Debian Linux: version 8.0 only
  • Strongswan Strongswan: version 4.3.0 only; version 4.3.1 only; version 4.3.2 only; version 4.3.3 only; version 4.3.4 only; version 4.3.5 only; …
  • Strongswan Strongswan VPN Client: up to and including 1.4.5

Published 2015-06-10. Last modified 2026-06-17.