strongSwan vulnerability

strongSwan 4.5.0 through 6.0.7 has Incorrect Access Control in the eap-ttls and eap-peap plugins because there can be a missing or mismatched inner EAP identity.

Published 11 Sep 2026Updated 11 Sep 20262 sources
CVSS 7.1

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.