HIGH · 7.5

CVE-2021-41991

The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to fill the cache and later trigger the replacement of...

Vulnerability Description

The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to fill the cache and later trigger the replacement of cache entries. The code attempts to select a less-often-used cache entry by means of a random number generator, but this is not done correctly. Remote code execution might be a slight possibility.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
StrongswanStrongswan>= 4.2.10, < 5.9.4
DebianDebian Linux9.0
FedoraprojectFedora33
SiemensSinema Remote Connect Server-
SiemensSiplus Et 200Sp Cp 1542Sp-1 Irc Tx Rail Firmware-
SiemensSiplus Et 200Sp Cp 1542Sp-1 Irc Tx Rail-
SiemensSimatic Cp 1243-1 Firmware-
SiemensSimatic Cp 1243-1-
SiemensSimatic Cp 1242-7 Gprs V2 Firmware-
SiemensSimatic Cp 1242-7 Gprs V2-
SiemensSimatic Net Cp 1243-8 Irc Firmware-
SiemensSimatic Net Cp 1243-8 Irc-
SiemensScalance Sc632-2C Firmware-
SiemensScalance Sc632-2C-
SiemensSiplus Et 200Sp Cp 1543Sp-1 Isec Firmware-
SiemensSiplus Et 200Sp Cp 1543Sp-1 Isec-
SiemensCp 1543-1 Firmware-
SiemensCp 1543-1-
SiemensSimatic Net Cp 1545-1 Firmware-
SiemensSimatic Net Cp 1545-1-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-41991?

CVE-2021-41991 is a vulnerability with a CVSS score of 7.5 (HIGH). The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to fill the cache and later trigger the replacement of...

How severe is CVE-2021-41991?

CVE-2021-41991 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-41991?

Check the references section above for vendor advisories and patch information. Affected products include: Strongswan Strongswan, Debian Debian Linux, Fedoraproject Fedora, Siemens Sinema Remote Connect Server, Siemens Siplus Et 200Sp Cp 1542Sp-1 Irc Tx Rail Firmware.