CVE-2015-8023

The server implementation of the EAP-MSCHAPv2 protocol in the eap-mschapv2 plugin in strongSwan 4.2.12 through 5.x before 5.3.4 does not properly validate local state, which allows remote attackers to bypass authentication via an empty Success message in response to an initial Challenge message.

Published: 2015-11-18 Last update: 2026-05-06 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2015-8023 is rated Moderate Risk (45.8/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 0.80%). Mandatory action: Review affected assets and schedule remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2015-8023

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2025-06-28 0.52% 0.80% +0.28%
2 2025-03-30 1.36% 0.52% -0.84%
3 2025-03-29 1.36%

Full EPSS history (5 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2015-8023

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
5.0 2.0 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:N)
No confidentiality impact.
Integrity impact (I:P)
Partial integrity impact.
Availability impact (A:N)
No availability impact.
10.0 2.9 [email protected]

Weakness enumeration for CVE-2015-8023

OS Trackers for CVE-2015-8023

vendor priority summary link
debian not yet assigned CVE-2015-8023 not yet assigned priority: Debian including 1 source packages (strongswan), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. https://security-tracker.debian.org/tracker/CVE-2015-8023
redhat high https://access.redhat.com/security/cve/CVE-2015-8023
suse high CVE-2015-8023 severity important: SUSE including 75 source package names (strongswan, strongswan-4.4.0-6.32.1, …), 190 product×package rows across 50 product lines (SUSE CaaS Platform 4.0, SUSE Enterprise Storage 6, … (50 product lines)): Fixed 149, Known Not Affected 41. https://www.suse.com/security/cve/CVE-2015-8023/
ubuntu medium CVE-2015-8023 medium priority: Ubuntu including 1 source packages (strongswan), 8 status rows across 8 suites (precise, trusty, upstream, vivid, wily, xenial, yakkety, zesty): released 7, ignored 1. https://ubuntu.com/security/CVE-2015-8023

Affected software / configurations for CVE-2015-8023

Vendor Product Version Raw CPE
canonical ubuntu_linux 14.04 cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
canonical ubuntu_linux 15.04 cpe:2.3:o:canonical:ubuntu_linux:15.04:*:*:*:*:*:*:*
canonical ubuntu_linux 15.10 cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*
strongswan strongswan 4.2.12 cpe:2.3:a:strongswan:strongswan:4.2.12:*:*:*:*:*:*:*
strongswan strongswan 4.2.13 cpe:2.3:a:strongswan:strongswan:4.2.13:*:*:*:*:*:*:*
strongswan strongswan 4.2.14 cpe:2.3:a:strongswan:strongswan:4.2.14:*:*:*:*:*:*:*
strongswan strongswan 4.2.15 cpe:2.3:a:strongswan:strongswan:4.2.15:*:*:*:*:*:*:*
strongswan strongswan 4.2.16 cpe:2.3:a:strongswan:strongswan:4.2.16:*:*:*:*:*:*:*
strongswan strongswan 4.3.0 cpe:2.3:a:strongswan:strongswan:4.3.0:*:*:*:*:*:*:*
strongswan strongswan 4.3.1 cpe:2.3:a:strongswan:strongswan:4.3.1:*:*:*:*:*:*:*
strongswan strongswan 4.3.2 cpe:2.3:a:strongswan:strongswan:4.3.2:*:*:*:*:*:*:*
strongswan strongswan 4.3.3 cpe:2.3:a:strongswan:strongswan:4.3.3:*:*:*:*:*:*:*
strongswan strongswan 4.3.4 cpe:2.3:a:strongswan:strongswan:4.3.4:*:*:*:*:*:*:*
strongswan strongswan 4.3.5 cpe:2.3:a:strongswan:strongswan:4.3.5:*:*:*:*:*:*:*
strongswan strongswan 4.3.6 cpe:2.3:a:strongswan:strongswan:4.3.6:*:*:*:*:*:*:*
strongswan strongswan 4.3.7 cpe:2.3:a:strongswan:strongswan:4.3.7:*:*:*:*:*:*:*
strongswan strongswan 4.4.0 cpe:2.3:a:strongswan:strongswan:4.4.0:*:*:*:*:*:*:*
strongswan strongswan 4.4.1 cpe:2.3:a:strongswan:strongswan:4.4.1:*:*:*:*:*:*:*
strongswan strongswan 4.5.0 cpe:2.3:a:strongswan:strongswan:4.5.0:*:*:*:*:*:*:*
strongswan strongswan 4.5.1 cpe:2.3:a:strongswan:strongswan:4.5.1:*:*:*:*:*:*:*
strongswan strongswan 4.5.2 cpe:2.3:a:strongswan:strongswan:4.5.2:*:*:*:*:*:*:*
strongswan strongswan 4.5.3 cpe:2.3:a:strongswan:strongswan:4.5.3:*:*:*:*:*:*:*
strongswan strongswan 4.6.0 cpe:2.3:a:strongswan:strongswan:4.6.0:*:*:*:*:*:*:*
strongswan strongswan 4.6.1 cpe:2.3:a:strongswan:strongswan:4.6.1:*:*:*:*:*:*:*
strongswan strongswan 4.6.2 cpe:2.3:a:strongswan:strongswan:4.6.2:*:*:*:*:*:*:*
strongswan strongswan 4.6.3 cpe:2.3:a:strongswan:strongswan:4.6.3:*:*:*:*:*:*:*
strongswan strongswan 4.6.4 cpe:2.3:a:strongswan:strongswan:4.6.4:*:*:*:*:*:*:*
strongswan strongswan 5.0.0 cpe:2.3:a:strongswan:strongswan:5.0.0:*:*:*:*:*:*:*
strongswan strongswan 5.0.1 cpe:2.3:a:strongswan:strongswan:5.0.1:*:*:*:*:*:*:*
strongswan strongswan 5.0.2 cpe:2.3:a:strongswan:strongswan:5.0.2:*:*:*:*:*:*:*
strongswan strongswan 5.0.3 cpe:2.3:a:strongswan:strongswan:5.0.3:*:*:*:*:*:*:*
strongswan strongswan 5.0.4 cpe:2.3:a:strongswan:strongswan:5.0.4:*:*:*:*:*:*:*
strongswan strongswan 5.1.0 cpe:2.3:a:strongswan:strongswan:5.1.0:*:*:*:*:*:*:*
strongswan strongswan 5.1.1 cpe:2.3:a:strongswan:strongswan:5.1.1:*:*:*:*:*:*:*
strongswan strongswan 5.1.2 cpe:2.3:a:strongswan:strongswan:5.1.2:*:*:*:*:*:*:*
strongswan strongswan 5.1.3 cpe:2.3:a:strongswan:strongswan:5.1.3:*:*:*:*:*:*:*
strongswan strongswan 5.2.0 cpe:2.3:a:strongswan:strongswan:5.2.0:*:*:*:*:*:*:*
strongswan strongswan 5.2.1 cpe:2.3:a:strongswan:strongswan:5.2.1:*:*:*:*:*:*:*
strongswan strongswan 5.2.2 cpe:2.3:a:strongswan:strongswan:5.2.2:*:*:*:*:*:*:*
strongswan strongswan 5.2.3 cpe:2.3:a:strongswan:strongswan:5.2.3:*:*:*:*:*:*:*
strongswan strongswan 5.3.0 cpe:2.3:a:strongswan:strongswan:5.3.0:*:*:*:*:*:*:*
strongswan strongswan 5.3.1 cpe:2.3:a:strongswan:strongswan:5.3.1:*:*:*:*:*:*:*
strongswan strongswan 5.3.2 cpe:2.3:a:strongswan:strongswan:5.3.2:*:*:*:*:*:*:*
strongswan strongswan 5.3.3 cpe:2.3:a:strongswan:strongswan:5.3.3:*:*:*:*:*:*:*

References for CVE-2015-8023

cvelogic Threat Intelligence