EudorIACyber Intelligence
Monitoraggio operativo Newsletter IT EN
← Torna all'intelligence
Avviso tecnico

USN-8789-1: strongSwan vulnerabilities

Fonte ufficiale
Sintesi operativa EudorIA

Cosa significa

Priorità 70/100

Ubuntu ha rilasciato un avviso di sicurezza (USN-8789-1) riguardante vulnerabilità in strongSwan, un'implementazione IPsec VPN. Le vulnerabilità permettono a un attaccante remoto di causare un denial of service o ottenere informazioni sensibili. Le patch sono disponibili per diverse versioni di strongSwan.

Perché conta

Per le PMI italiane, queste vulnerabilità possono compromettere la disponibilità e la riservatezza dei dati, specialmente se strongSwan è utilizzato per la gestione di connessioni sicure. L'aggiornamento delle versioni è fondamentale per mitigare i rischi.

MITRE ATT&CKT1562 · Impair Defenses *T1486 · Data Encrypted for Impact *
Brief generato da un modello locale EudorIA (qwen3:8b@workstation-gpu) a partire dal testo della fonte. Verificare sulla fonte prima di decisioni operative; le tecniche con * sono inferite dal modello. Testo parziale, dettagli non completi, fonte editoriale non specificata con precisione.

Estratto della fonte usato dal modello

Your submission was sent successfully! Close Thank you for contacting us. A member of our team will be in touch shortly. Close You have successfully unsubscribed! Close Thank you for signing up for our newsletter! In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team. Close Your preferences have been successfully updated. Close notification Please try again or file a bug report. Close USN-8789-1: strongSwan vulnerabilities Several security issues were fixed in strongSwan. strongswan - IPsec VPN solution It was discovered that strongSwan incorrectly handled PKCS#7 containers in the openssl plugin. A remote attacker could possibly use this issue to cause strongSwan to crash, resulting in a denial of service. ( CVE-2026-78123 ) It was discovered that strongSwan incorrectly handled memory when enumerating certificates in PKCS#7 containers in the openssl plugin. A remote attacker could possibly use this issue to obtain sensitive information. ( CVE-2026-78124 ) It was discovered that strongSwan incorrectly handled AKA-Synchronization-Failure messages in the eap-aka plugin. A remote attacker could possibly use this issue to cause strongSwan to crash, resulting in a denial of service. ( CVE-2026-78126 ) It was discovered that strongSwan incorrectly handled memory when stringifying IKE messages. A remote attacker... It was discovered that strongSwan incorrectly handled PKCS#7 containers in the openssl plugin. A remote att

Benefici operativi potenziali

  • Riduzione della superficie esposta
  • Miglioramento della disponibilità dei servizi
  • Protezione dei dati sensibili
  • Riduzione del rischio di attacchi di DoS
Indicazioni da confermare sul perimetro tecnico e organizzativo del cliente.
Controlli pertinentiPatch managementFirewall NGFW / IPSMonitoraggio / SIEMBackup & DRSegmentazione di rete
DestinatariITSOCCISO
Centro informazioni

Traduzione in elaborazione

Ubuntu Security

Il contenuto ufficiale è disponibile nella lingua originale. La versione italiana verrà pubblicata al termine dei controlli automatici.

Testo acquisito dalla fonte

It was discovered that strongSwan incorrectly handled PKCS#7 containers in the openssl plugin. A remote attacker could possibly use this issue to cause strongSwan to crash, resulting in a denial of service. (CVE-2026-78123) It was discovered that strongSwan incorrectly handled memory when enumerating certificates in PKCS#7 containers in the openssl plugin. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2026-78124) It was discovered that strongSwan incorrectly handled AKA-Synchronization-Failure messages in the eap-aka plugin. A remote attacker could possibly use this issue to cause strongSwan to crash, resulting in a denial of service. (CVE-2026-78126) It was discovered that strongSwan incorrectly handled memory when stringifying IKE messages. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2026-78127) It was discovered that strongSwan incorrectly handled PKCS#5 decryption. A remote attacker could possibly use this issue to cause strongSwan to consume excessive resources, leading to a denial of service. (CVE-2026-78129) It was discovered that strongSwan incorrectly handled attribute certificates in the x509 plugin when the issuer name was missing. A remote attacker could possibly use this issue to cause strongSwan to crash, resulting in a denial of service. (CVE-2026-78130) It was discovered that strongSwan incorrectly handled memory when parsing attribute certificates in the x509 plugin. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2026-78131) It was discovered that strongSwan incorrectly handled attribute certificates containing ietfAttrSyntax values in the x509 plugin. A remote attacker could possibly use this issue to cause strongSwan to consume exce

Fonte
Ubuntu Security Notices
Entità pubblicatrice
Ubuntu Security
Tipo entità
vendor security
Area
Global
Lingua originale
en · traduzione in preparazione
Pubblicazione
21/09/2026 14:16
MITRE ATT&CK
T1562, T1486
CVE
CVE-2026-78123, CVE-2026-78124, CVE-2026-78126, CVE-2026-78127, CVE-2026-78129, CVE-2026-78130, CVE-2026-78131
Perimetro tecnico

Prodotti e versioni interessati

Verifica in corso
Informazione non ancora acquisita.

Il collector verificherà NVD e gli advisory vendor ufficiali disponibili.

Apri la fonte originale