← Vulnerability feed

Vulnerability record · CVE-2023-41913 · published 7 December 2023

CVE-2023-41913: Strongswan classic buffer overflow vulnerability

Strongswan · Strongswan

strongSwan before 5.9.12 has a buffer overflow and possible unauthenticated remote code execution via a DH public value that exceeds the internal buffer in charon-tkm's DH proxy. The earliest affected version is 5.3.0. An attack can occur via a crafted IKE_SA_INIT message.

9.8 CVSS 3.1 Critical EPSS 2.3% · top 17.3% CWE-120 · Classic buffer overflow
9.8CVSS 3.1 base score
2.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
9References
17 Jun 2026Last modified by NVD

Description

strongSwan before 5.9.12 has a buffer overflow and possible unauthenticated remote code execution via a DH public value that exceeds the internal buffer in charon-tkm's DH proxy. The earliest affected version is 5.3.0. An attack can occur via a crafted IKE_SA_INIT message.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-41913 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2004-0590Frees wan vulnerabilityFreeS/WAN 1.x and 2.x, and other related products including superfreeswan 1.x, openswan 1.x before 1.0.6, openswan 2.x before 2.1.4, and strongSwan b…EPSS 2.8%9.8CVE-2023-26463Strongswan improper certificate validation vulnerabilitystrongSwan 5.9.8 and 5.9.9 potentially allows remote code execution because it uses a variable named "public" for two different purposes within the s…EPSS 2.3%9.8CVE-2015-3991Strongswan vulnerabilitystrongSwan 5.2.2 and 5.3.0 allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code.EPSS 4.6%9.1CVE-2021-45079Strongswan null pointer dereference vulnerabilityIn strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticating the client and (in the ca…EPSS 2.8%7.5CVE-2026-78130Strongswan null pointer dereference vulnerabilitystrongSwan 4.2.0 through 6.0.7 has a NULL pointer dereference in the x509 plugin's attribute certificate parser.EPSS 0.32%7.5CVE-2026-78132Strongswan vulnerabilitystrongSwan 5.1.3 through 6.0.7 has an infinite loop in the x509 plugin's attribute certificate parser for ietfAttrSyntax.EPSS 0.32%7.5CVE-2026-78133Strongswan use after free vulnerabilitylibcharon in strongSwan 6.0.0 through 6.0.7 has a use-after-free in IKEv2 rekeying collision handling.EPSS 0.43%7.5CVE-2022-40617Strongswan uncontrolled resource consumption vulnerabilitystrongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a crafted end-entity (and intermedia…EPSS 1.7%

Source: NIST National Vulnerability Database (record CVE-2023-41913), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.