Ruijie Networks EG306MG Missing Encryption Vulnerability in strongSwan Configuration

Vulnerability

A vulnerability exists in the Ruijie Networks EG306MG version 3.0(1)B11P309, specifically within the strongSwan component. The issue arises from a misconfiguration in the strongSwan configuration file, /etc/strongswan.conf. The vulnerability allows the use of IKEv1 Aggressive Mode with Pre-Shared Keys, which could lead to offline attacks on the transmitted hash of the PSK. This vulnerability allows for missing encryption of sensitive data, with the potential for remote exploitation.

Impact

Exploitation of this vulnerability could result in missing encryption of sensitive data, allowing for interception and potential misuse of unprotected information.

Reproduction

The vulnerability can be reproduced by enabling the 'i_dont_care_about_security_and_use_aggressive_mode_psk' property in the strongSwan configuration file. This setting allows IKE Responders to use IKEv1 Aggressive Mode with Pre-Shared Keys, creating a vulnerability that could be exploited offline.

Added: Aug 9, 2025, 6:17 PM
Updated: Aug 9, 2025, 6:17 PM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
2.5
exploitability
8.6
remediation
0.0
relevance
0.3
threat
1.6
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.