HIGH · 7.5

CVE-2021-41990

The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example, this can be triggered by an unrelated self-signed CA certif...

Vulnerability Description

The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example, this can be triggered by an unrelated self-signed CA certificate sent by an initiator. Remote code execution cannot occur.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
StrongswanStrongswan>= 5.6.1, < 5.9.4
DebianDebian Linux10.0
FedoraprojectFedora33
Siemens6Gk6108-4Am00-2Ba2 Firmware-
Siemens6Gk6108-4Am00-2Ba2-
Siemens6Gk6108-4Am00-2Da2 Firmware-
Siemens6Gk6108-4Am00-2Da2-
Siemens6Gk5804-0Ap00-2Aa2 Firmware-
Siemens6Gk5804-0Ap00-2Aa2-
Siemens6Gk5812-1Aa00-2Aa2 Firmware-
Siemens6Gk5812-1Aa00-2Aa2-
Siemens6Gk5812-1Ba00-2Aa2 Firmware-
Siemens6Gk5812-1Ba00-2Aa2-
Siemens6Gk5816-1Aa00-2Aa2 Firmware-
Siemens6Gk5816-1Aa00-2Aa2-
Siemens6Gk5816-1Ba00-2Aa2 Firmware-
Siemens6Gk5816-1Ba00-2Aa2-
Siemens6Gk5826-2Ab00-2Ab2 Firmware-
Siemens6Gk5826-2Ab00-2Ab2-
Siemens6Gk5874-2Aa00-2Aa2 Firmware-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-41990?

CVE-2021-41990 is a vulnerability with a CVSS score of 7.5 (HIGH). The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example, this can be triggered by an unrelated self-signed CA certif...

How severe is CVE-2021-41990?

CVE-2021-41990 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-41990?

Check the references section above for vendor advisories and patch information. Affected products include: Strongswan Strongswan, Debian Debian Linux, Fedoraproject Fedora, Siemens 6Gk6108-4Am00-2Ba2 Firmware, Siemens 6Gk6108-4Am00-2Ba2.