CVE-2021-41991
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to fill the cache and later trigger the replacement of cache entries. The code attempts to select a less-often-used cache entry by means of a random number generator, but this is not done correctly. Remote code execution might be a slight possibility.
La caché de certificados en memoria en strongSwan versiones anteriores a 5.9.4, presenta un desbordamiento de enteros remoto al recibir muchas peticiones con diferentes certificados para llenar la caché y posteriormente desencadenar la sustitución de las entradas de la caché. El código intenta seleccionar una entrada de caché menos usada mediante un generador de números aleatorios, pero esto no es realizado correctamente. Una ejecución de código remota podría ser una pequeña posibilidad
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-10-04 CVE Reserved
- 2021-10-18 CVE Published
- 2024-07-03 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-190: Integer Overflow or Wraparound
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
https://github.com/strongswan/strongswan/releases/tag/5.9.4 | Third Party Advisory | |
https://lists.debian.org/debian-lts-announce/2021/10/msg00014.html | Mailing List | |
https://www.strongswan.org/blog/2021/10/18/strongswan-vulnerability-%28cve-2021-41991%29.html | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://cert-portal.siemens.com/productcert/pdf/ssa-539476.pdf | 2023-11-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Siemens Search vendor "Siemens" | Siplus Et 200sp Cp 1542sp-1 Irc Tx Rail Firmware Search vendor "Siemens" for product "Siplus Et 200sp Cp 1542sp-1 Irc Tx Rail Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Siplus Et 200sp Cp 1542sp-1 Irc Tx Rail Search vendor "Siemens" for product "Siplus Et 200sp Cp 1542sp-1 Irc Tx Rail" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Cp 1243-1 Firmware Search vendor "Siemens" for product "Simatic Cp 1243-1 Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Cp 1243-1 Search vendor "Siemens" for product "Simatic Cp 1243-1" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Cp 1242-7 Gprs V2 Firmware Search vendor "Siemens" for product "Simatic Cp 1242-7 Gprs V2 Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Cp 1242-7 Gprs V2 Search vendor "Siemens" for product "Simatic Cp 1242-7 Gprs V2" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Net Cp 1243-8 Irc Firmware Search vendor "Siemens" for product "Simatic Net Cp 1243-8 Irc Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Net Cp 1243-8 Irc Search vendor "Siemens" for product "Simatic Net Cp 1243-8 Irc" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Scalance Sc632-2c Firmware Search vendor "Siemens" for product "Scalance Sc632-2c Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Scalance Sc632-2c Search vendor "Siemens" for product "Scalance Sc632-2c" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Siplus Et 200sp Cp 1543sp-1 Isec Firmware Search vendor "Siemens" for product "Siplus Et 200sp Cp 1543sp-1 Isec Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Siplus Et 200sp Cp 1543sp-1 Isec Search vendor "Siemens" for product "Siplus Et 200sp Cp 1543sp-1 Isec" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Cp 1543-1 Firmware Search vendor "Siemens" for product "Cp 1543-1 Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Cp 1543-1 Search vendor "Siemens" for product "Cp 1543-1" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Net Cp 1545-1 Firmware Search vendor "Siemens" for product "Simatic Net Cp 1545-1 Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Net Cp 1545-1 Search vendor "Siemens" for product "Simatic Net Cp 1545-1" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Cp 1543sp-1 Firmware Search vendor "Siemens" for product "Simatic Cp 1543sp-1 Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Cp 1543sp-1 Search vendor "Siemens" for product "Simatic Cp 1543sp-1" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Net Cp1243-7 Lte Eu Firmware Search vendor "Siemens" for product "Simatic Net Cp1243-7 Lte Eu Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Net Cp1243-7 Lte Eu Search vendor "Siemens" for product "Simatic Net Cp1243-7 Lte Eu" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Cp 1243-7 Lte\/us Firmware Search vendor "Siemens" for product "Simatic Cp 1243-7 Lte\/us Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Cp 1243-7 Lte\/us Search vendor "Siemens" for product "Simatic Cp 1243-7 Lte\/us" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Cp 1542sp-1 Firmware Search vendor "Siemens" for product "Simatic Cp 1542sp-1 Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Cp 1542sp-1 Search vendor "Siemens" for product "Simatic Cp 1542sp-1" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Scalance Sc636-2c Firmware Search vendor "Siemens" for product "Scalance Sc636-2c Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Scalance Sc636-2c Search vendor "Siemens" for product "Scalance Sc636-2c" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Cp 1542sp-1 Irc Firmware Search vendor "Siemens" for product "Simatic Cp 1542sp-1 Irc Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Cp 1542sp-1 Irc Search vendor "Siemens" for product "Simatic Cp 1542sp-1 Irc" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Scalance Sc642-2c Firmware Search vendor "Siemens" for product "Scalance Sc642-2c Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Scalance Sc642-2c Search vendor "Siemens" for product "Scalance Sc642-2c" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Scalance Sc646-2c Firmware Search vendor "Siemens" for product "Scalance Sc646-2c Firmware" | < 2.3 Search vendor "Siemens" for product "Scalance Sc646-2c Firmware" and version " < 2.3" | - |
Affected
| in | Siemens Search vendor "Siemens" | Scalance Sc646-2c Search vendor "Siemens" for product "Scalance Sc646-2c" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Scalance Sc622-2c Firmware Search vendor "Siemens" for product "Scalance Sc622-2c Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Scalance Sc622-2c Search vendor "Siemens" for product "Scalance Sc622-2c" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Siplus S7-1200 Cp 1243-1 Rail Firmware Search vendor "Siemens" for product "Siplus S7-1200 Cp 1243-1 Rail Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Siplus S7-1200 Cp 1243-1 Rail Search vendor "Siemens" for product "Siplus S7-1200 Cp 1243-1 Rail" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Siplus S7-1200 Cp 1243-1 Firmware Search vendor "Siemens" for product "Siplus S7-1200 Cp 1243-1 Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Siplus S7-1200 Cp 1243-1 Search vendor "Siemens" for product "Siplus S7-1200 Cp 1243-1" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Siplus Net Cp 1543-1 Firmware Search vendor "Siemens" for product "Siplus Net Cp 1543-1 Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Siplus Net Cp 1543-1 Search vendor "Siemens" for product "Siplus Net Cp 1543-1" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Siplus Et 200sp Cp 1543sp-1 Isec Tx Rail Firmware Search vendor "Siemens" for product "Siplus Et 200sp Cp 1543sp-1 Isec Tx Rail Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Siplus Et 200sp Cp 1543sp-1 Isec Tx Rail Search vendor "Siemens" for product "Siplus Et 200sp Cp 1543sp-1 Isec Tx Rail" | - | - |
Safe
|
Strongswan Search vendor "Strongswan" | Strongswan Search vendor "Strongswan" for product "Strongswan" | >= 4.2.10 < 5.9.4 Search vendor "Strongswan" for product "Strongswan" and version " >= 4.2.10 < 5.9.4" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 9.0 Search vendor "Debian" for product "Debian Linux" and version "9.0" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 10.0 Search vendor "Debian" for product "Debian Linux" and version "10.0" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 11.0 Search vendor "Debian" for product "Debian Linux" and version "11.0" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 33 Search vendor "Fedoraproject" for product "Fedora" and version "33" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 34 Search vendor "Fedoraproject" for product "Fedora" and version "34" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 35 Search vendor "Fedoraproject" for product "Fedora" and version "35" | - |
Affected
| ||||||
Siemens Search vendor "Siemens" | Sinema Remote Connect Server Search vendor "Siemens" for product "Sinema Remote Connect Server" | - | - |
Affected
|