// For flags

CVE-2021-41991

 

Severity Score

7.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to fill the cache and later trigger the replacement of cache entries. The code attempts to select a less-often-used cache entry by means of a random number generator, but this is not done correctly. Remote code execution might be a slight possibility.

La caché de certificados en memoria en strongSwan versiones anteriores a 5.9.4, presenta un desbordamiento de enteros remoto al recibir muchas peticiones con diferentes certificados para llenar la caché y posteriormente desencadenar la sustitución de las entradas de la caché. El código intenta seleccionar una entrada de caché menos usada mediante un generador de números aleatorios, pero esto no es realizado correctamente. Una ejecución de código remota podría ser una pequeña posibilidad

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2021-10-04 CVE Reserved
  • 2021-10-18 CVE Published
  • 2024-07-03 EPSS Updated
  • 2024-08-04 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-190: Integer Overflow or Wraparound
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Siemens
Search vendor "Siemens"
Siplus Et 200sp Cp 1542sp-1 Irc Tx Rail Firmware
Search vendor "Siemens" for product "Siplus Et 200sp Cp 1542sp-1 Irc Tx Rail Firmware"
--
Affected
in Siemens
Search vendor "Siemens"
Siplus Et 200sp Cp 1542sp-1 Irc Tx Rail
Search vendor "Siemens" for product "Siplus Et 200sp Cp 1542sp-1 Irc Tx Rail"
--
Safe
Siemens
Search vendor "Siemens"
Simatic Cp 1243-1 Firmware
Search vendor "Siemens" for product "Simatic Cp 1243-1 Firmware"
--
Affected
in Siemens
Search vendor "Siemens"
Simatic Cp 1243-1
Search vendor "Siemens" for product "Simatic Cp 1243-1"
--
Safe
Siemens
Search vendor "Siemens"
Simatic Cp 1242-7 Gprs V2 Firmware
Search vendor "Siemens" for product "Simatic Cp 1242-7 Gprs V2 Firmware"
--
Affected
in Siemens
Search vendor "Siemens"
Simatic Cp 1242-7 Gprs V2
Search vendor "Siemens" for product "Simatic Cp 1242-7 Gprs V2"
--
Safe
Siemens
Search vendor "Siemens"
Simatic Net Cp 1243-8 Irc Firmware
Search vendor "Siemens" for product "Simatic Net Cp 1243-8 Irc Firmware"
--
Affected
in Siemens
Search vendor "Siemens"
Simatic Net Cp 1243-8 Irc
Search vendor "Siemens" for product "Simatic Net Cp 1243-8 Irc"
--
Safe
Siemens
Search vendor "Siemens"
Scalance Sc632-2c Firmware
Search vendor "Siemens" for product "Scalance Sc632-2c Firmware"
--
Affected
in Siemens
Search vendor "Siemens"
Scalance Sc632-2c
Search vendor "Siemens" for product "Scalance Sc632-2c"
--
Safe
Siemens
Search vendor "Siemens"
Siplus Et 200sp Cp 1543sp-1 Isec Firmware
Search vendor "Siemens" for product "Siplus Et 200sp Cp 1543sp-1 Isec Firmware"
--
Affected
in Siemens
Search vendor "Siemens"
Siplus Et 200sp Cp 1543sp-1 Isec
Search vendor "Siemens" for product "Siplus Et 200sp Cp 1543sp-1 Isec"
--
Safe
Siemens
Search vendor "Siemens"
Cp 1543-1 Firmware
Search vendor "Siemens" for product "Cp 1543-1 Firmware"
--
Affected
in Siemens
Search vendor "Siemens"
Cp 1543-1
Search vendor "Siemens" for product "Cp 1543-1"
--
Safe
Siemens
Search vendor "Siemens"
Simatic Net Cp 1545-1 Firmware
Search vendor "Siemens" for product "Simatic Net Cp 1545-1 Firmware"
--
Affected
in Siemens
Search vendor "Siemens"
Simatic Net Cp 1545-1
Search vendor "Siemens" for product "Simatic Net Cp 1545-1"
--
Safe
Siemens
Search vendor "Siemens"
Simatic Cp 1543sp-1 Firmware
Search vendor "Siemens" for product "Simatic Cp 1543sp-1 Firmware"
--
Affected
in Siemens
Search vendor "Siemens"
Simatic Cp 1543sp-1
Search vendor "Siemens" for product "Simatic Cp 1543sp-1"
--
Safe
Siemens
Search vendor "Siemens"
Simatic Net Cp1243-7 Lte Eu Firmware
Search vendor "Siemens" for product "Simatic Net Cp1243-7 Lte Eu Firmware"
--
Affected
in Siemens
Search vendor "Siemens"
Simatic Net Cp1243-7 Lte Eu
Search vendor "Siemens" for product "Simatic Net Cp1243-7 Lte Eu"
--
Safe
Siemens
Search vendor "Siemens"
Simatic Cp 1243-7 Lte\/us Firmware
Search vendor "Siemens" for product "Simatic Cp 1243-7 Lte\/us Firmware"
--
Affected
in Siemens
Search vendor "Siemens"
Simatic Cp 1243-7 Lte\/us
Search vendor "Siemens" for product "Simatic Cp 1243-7 Lte\/us"
--
Safe
Siemens
Search vendor "Siemens"
Simatic Cp 1542sp-1 Firmware
Search vendor "Siemens" for product "Simatic Cp 1542sp-1 Firmware"
--
Affected
in Siemens
Search vendor "Siemens"
Simatic Cp 1542sp-1
Search vendor "Siemens" for product "Simatic Cp 1542sp-1"
--
Safe
Siemens
Search vendor "Siemens"
Scalance Sc636-2c Firmware
Search vendor "Siemens" for product "Scalance Sc636-2c Firmware"
--
Affected
in Siemens
Search vendor "Siemens"
Scalance Sc636-2c
Search vendor "Siemens" for product "Scalance Sc636-2c"
--
Safe
Siemens
Search vendor "Siemens"
Simatic Cp 1542sp-1 Irc Firmware
Search vendor "Siemens" for product "Simatic Cp 1542sp-1 Irc Firmware"
--
Affected
in Siemens
Search vendor "Siemens"
Simatic Cp 1542sp-1 Irc
Search vendor "Siemens" for product "Simatic Cp 1542sp-1 Irc"
--
Safe
Siemens
Search vendor "Siemens"
Scalance Sc642-2c Firmware
Search vendor "Siemens" for product "Scalance Sc642-2c Firmware"
--
Affected
in Siemens
Search vendor "Siemens"
Scalance Sc642-2c
Search vendor "Siemens" for product "Scalance Sc642-2c"
--
Safe
Siemens
Search vendor "Siemens"
Scalance Sc646-2c Firmware
Search vendor "Siemens" for product "Scalance Sc646-2c Firmware"
< 2.3
Search vendor "Siemens" for product "Scalance Sc646-2c Firmware" and version " < 2.3"
-
Affected
in Siemens
Search vendor "Siemens"
Scalance Sc646-2c
Search vendor "Siemens" for product "Scalance Sc646-2c"
--
Safe
Siemens
Search vendor "Siemens"
Scalance Sc622-2c Firmware
Search vendor "Siemens" for product "Scalance Sc622-2c Firmware"
--
Affected
in Siemens
Search vendor "Siemens"
Scalance Sc622-2c
Search vendor "Siemens" for product "Scalance Sc622-2c"
--
Safe
Siemens
Search vendor "Siemens"
Siplus S7-1200 Cp 1243-1 Rail Firmware
Search vendor "Siemens" for product "Siplus S7-1200 Cp 1243-1 Rail Firmware"
--
Affected
in Siemens
Search vendor "Siemens"
Siplus S7-1200 Cp 1243-1 Rail
Search vendor "Siemens" for product "Siplus S7-1200 Cp 1243-1 Rail"
--
Safe
Siemens
Search vendor "Siemens"
Siplus S7-1200 Cp 1243-1 Firmware
Search vendor "Siemens" for product "Siplus S7-1200 Cp 1243-1 Firmware"
--
Affected
in Siemens
Search vendor "Siemens"
Siplus S7-1200 Cp 1243-1
Search vendor "Siemens" for product "Siplus S7-1200 Cp 1243-1"
--
Safe
Siemens
Search vendor "Siemens"
Siplus Net Cp 1543-1 Firmware
Search vendor "Siemens" for product "Siplus Net Cp 1543-1 Firmware"
--
Affected
in Siemens
Search vendor "Siemens"
Siplus Net Cp 1543-1
Search vendor "Siemens" for product "Siplus Net Cp 1543-1"
--
Safe
Siemens
Search vendor "Siemens"
Siplus Et 200sp Cp 1543sp-1 Isec Tx Rail Firmware
Search vendor "Siemens" for product "Siplus Et 200sp Cp 1543sp-1 Isec Tx Rail Firmware"
--
Affected
in Siemens
Search vendor "Siemens"
Siplus Et 200sp Cp 1543sp-1 Isec Tx Rail
Search vendor "Siemens" for product "Siplus Et 200sp Cp 1543sp-1 Isec Tx Rail"
--
Safe
Strongswan
Search vendor "Strongswan"
Strongswan
Search vendor "Strongswan" for product "Strongswan"
>= 4.2.10 < 5.9.4
Search vendor "Strongswan" for product "Strongswan" and version " >= 4.2.10 < 5.9.4"
-
Affected
Debian
Search vendor "Debian"
Debian Linux
Search vendor "Debian" for product "Debian Linux"
9.0
Search vendor "Debian" for product "Debian Linux" and version "9.0"
-
Affected
Debian
Search vendor "Debian"
Debian Linux
Search vendor "Debian" for product "Debian Linux"
10.0
Search vendor "Debian" for product "Debian Linux" and version "10.0"
-
Affected
Debian
Search vendor "Debian"
Debian Linux
Search vendor "Debian" for product "Debian Linux"
11.0
Search vendor "Debian" for product "Debian Linux" and version "11.0"
-
Affected
Fedoraproject
Search vendor "Fedoraproject"
Fedora
Search vendor "Fedoraproject" for product "Fedora"
33
Search vendor "Fedoraproject" for product "Fedora" and version "33"
-
Affected
Fedoraproject
Search vendor "Fedoraproject"
Fedora
Search vendor "Fedoraproject" for product "Fedora"
34
Search vendor "Fedoraproject" for product "Fedora" and version "34"
-
Affected
Fedoraproject
Search vendor "Fedoraproject"
Fedora
Search vendor "Fedoraproject" for product "Fedora"
35
Search vendor "Fedoraproject" for product "Fedora" and version "35"
-
Affected
Siemens
Search vendor "Siemens"
Sinema Remote Connect Server
Search vendor "Siemens" for product "Sinema Remote Connect Server"
--
Affected