// For flags

CVE-2021-41990

 

Severity Score

7.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example, this can be triggered by an unrelated self-signed CA certificate sent by an initiator. Remote code execution cannot occur.

El plugin gmp en strongSwan versiones anteriores a 5.9.4, presenta un desbordamiento de enteros remoto por medio de un certificado diseñado con una firma RSASSA-PSS. Por ejemplo, esto puede ser desencadenado por un certificado de CA autofirmado no relacionado enviado por un iniciador. Una ejecución de código remota no puede ocurrir

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2021-10-04 CVE Reserved
  • 2021-10-18 CVE Published
  • 2024-07-03 EPSS Updated
  • 2024-08-04 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-190: Integer Overflow or Wraparound
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Siemens
Search vendor "Siemens"
6gk6108-4am00-2ba2 Firmware
Search vendor "Siemens" for product "6gk6108-4am00-2ba2 Firmware"
--
Affected
in Siemens
Search vendor "Siemens"
6gk6108-4am00-2ba2
Search vendor "Siemens" for product "6gk6108-4am00-2ba2"
--
Safe
Siemens
Search vendor "Siemens"
6gk6108-4am00-2da2 Firmware
Search vendor "Siemens" for product "6gk6108-4am00-2da2 Firmware"
--
Affected
in Siemens
Search vendor "Siemens"
6gk6108-4am00-2da2
Search vendor "Siemens" for product "6gk6108-4am00-2da2"
--
Safe
Siemens
Search vendor "Siemens"
6gk5804-0ap00-2aa2 Firmware
Search vendor "Siemens" for product "6gk5804-0ap00-2aa2 Firmware"
--
Affected
in Siemens
Search vendor "Siemens"
6gk5804-0ap00-2aa2
Search vendor "Siemens" for product "6gk5804-0ap00-2aa2"
--
Safe
Siemens
Search vendor "Siemens"
6gk5812-1aa00-2aa2 Firmware
Search vendor "Siemens" for product "6gk5812-1aa00-2aa2 Firmware"
--
Affected
in Siemens
Search vendor "Siemens"
6gk5812-1aa00-2aa2
Search vendor "Siemens" for product "6gk5812-1aa00-2aa2"
--
Safe
Siemens
Search vendor "Siemens"
6gk5812-1ba00-2aa2 Firmware
Search vendor "Siemens" for product "6gk5812-1ba00-2aa2 Firmware"
--
Affected
in Siemens
Search vendor "Siemens"
6gk5812-1ba00-2aa2
Search vendor "Siemens" for product "6gk5812-1ba00-2aa2"
--
Safe
Siemens
Search vendor "Siemens"
6gk5816-1aa00-2aa2 Firmware
Search vendor "Siemens" for product "6gk5816-1aa00-2aa2 Firmware"
--
Affected
in Siemens
Search vendor "Siemens"
6gk5816-1aa00-2aa2
Search vendor "Siemens" for product "6gk5816-1aa00-2aa2"
--
Safe
Siemens
Search vendor "Siemens"
6gk5816-1ba00-2aa2 Firmware
Search vendor "Siemens" for product "6gk5816-1ba00-2aa2 Firmware"
--
Affected
in Siemens
Search vendor "Siemens"
6gk5816-1ba00-2aa2
Search vendor "Siemens" for product "6gk5816-1ba00-2aa2"
--
Safe
Siemens
Search vendor "Siemens"
6gk5826-2ab00-2ab2 Firmware
Search vendor "Siemens" for product "6gk5826-2ab00-2ab2 Firmware"
--
Affected
in Siemens
Search vendor "Siemens"
6gk5826-2ab00-2ab2
Search vendor "Siemens" for product "6gk5826-2ab00-2ab2"
--
Safe
Siemens
Search vendor "Siemens"
6gk5874-2aa00-2aa2 Firmware
Search vendor "Siemens" for product "6gk5874-2aa00-2aa2 Firmware"
--
Affected
in Siemens
Search vendor "Siemens"
6gk5874-2aa00-2aa2
Search vendor "Siemens" for product "6gk5874-2aa00-2aa2"
--
Safe
Siemens
Search vendor "Siemens"
6gk5874-3aa00-2aa2 Firmware
Search vendor "Siemens" for product "6gk5874-3aa00-2aa2 Firmware"
--
Affected
in Siemens
Search vendor "Siemens"
6gk5874-3aa00-2aa2
Search vendor "Siemens" for product "6gk5874-3aa00-2aa2"
--
Safe
Siemens
Search vendor "Siemens"
6gk5876-3aa02-2ba2 Firmware
Search vendor "Siemens" for product "6gk5876-3aa02-2ba2 Firmware"
--
Affected
in Siemens
Search vendor "Siemens"
6gk5876-3aa02-2ba2
Search vendor "Siemens" for product "6gk5876-3aa02-2ba2"
--
Safe
Siemens
Search vendor "Siemens"
6gk5876-3aa02-2ea2 Firmware
Search vendor "Siemens" for product "6gk5876-3aa02-2ea2 Firmware"
--
Affected
in Siemens
Search vendor "Siemens"
6gk5876-3aa02-2ea2
Search vendor "Siemens" for product "6gk5876-3aa02-2ea2"
--
Safe
Siemens
Search vendor "Siemens"
6gk5876-4aa00-2ba2 Firmware
Search vendor "Siemens" for product "6gk5876-4aa00-2ba2 Firmware"
--
Affected
in Siemens
Search vendor "Siemens"
6gk5876-4aa00-2ba2
Search vendor "Siemens" for product "6gk5876-4aa00-2ba2"
--
Safe
Siemens
Search vendor "Siemens"
6gk5876-4aa00-2da2 Firmware
Search vendor "Siemens" for product "6gk5876-4aa00-2da2 Firmware"
--
Affected
in Siemens
Search vendor "Siemens"
6gk5876-4aa00-2da2
Search vendor "Siemens" for product "6gk5876-4aa00-2da2"
--
Safe
Siemens
Search vendor "Siemens"
6gk5856-2ea00-3da1 Firmware
Search vendor "Siemens" for product "6gk5856-2ea00-3da1 Firmware"
--
Affected
in Siemens
Search vendor "Siemens"
6gk5856-2ea00-3da1
Search vendor "Siemens" for product "6gk5856-2ea00-3da1"
--
Safe
Siemens
Search vendor "Siemens"
6gk5856-2ea00-3aa1 Firmware
Search vendor "Siemens" for product "6gk5856-2ea00-3aa1 Firmware"
--
Affected
in Siemens
Search vendor "Siemens"
6gk5856-2ea00-3aa1
Search vendor "Siemens" for product "6gk5856-2ea00-3aa1"
--
Safe
Siemens
Search vendor "Siemens"
6gk5615-0aa00-2aa2 Firmware
Search vendor "Siemens" for product "6gk5615-0aa00-2aa2 Firmware"
--
Affected
in Siemens
Search vendor "Siemens"
6gk5615-0aa00-2aa2
Search vendor "Siemens" for product "6gk5615-0aa00-2aa2"
--
Safe
Strongswan
Search vendor "Strongswan"
Strongswan
Search vendor "Strongswan" for product "Strongswan"
>= 5.6.1 < 5.9.4
Search vendor "Strongswan" for product "Strongswan" and version " >= 5.6.1 < 5.9.4"
-
Affected
Debian
Search vendor "Debian"
Debian Linux
Search vendor "Debian" for product "Debian Linux"
10.0
Search vendor "Debian" for product "Debian Linux" and version "10.0"
-
Affected
Debian
Search vendor "Debian"
Debian Linux
Search vendor "Debian" for product "Debian Linux"
11.0
Search vendor "Debian" for product "Debian Linux" and version "11.0"
-
Affected
Fedoraproject
Search vendor "Fedoraproject"
Fedora
Search vendor "Fedoraproject" for product "Fedora"
33
Search vendor "Fedoraproject" for product "Fedora" and version "33"
-
Affected
Fedoraproject
Search vendor "Fedoraproject"
Fedora
Search vendor "Fedoraproject" for product "Fedora"
34
Search vendor "Fedoraproject" for product "Fedora" and version "34"
-
Affected
Fedoraproject
Search vendor "Fedoraproject"
Fedora
Search vendor "Fedoraproject" for product "Fedora"
35
Search vendor "Fedoraproject" for product "Fedora" and version "35"
-
Affected