CVE-2021-41991
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to fill the cache and later trigger the replacement of cache entries. The code attempts to select a less-often-used cache entry by means of a random number generator, but this is not done correctly. Remote code execution might be a slight possibility.
Affected (29)
Show all products
Strongswan: Strongswan · Debian: Debian Linux · Fedoraproject: Fedora · Siemens: Sinema Remote Connect Server, Siplus Et 200sp Cp 1542sp 1 Irc Tx Rail Firmware, Simatic Cp 1243 1 Firmware, Simatic Cp 1242 7 Gprs V2 Firmware, Simatic Net Cp 1243 8 Irc Firmware, Scalance Sc632 2c Firmware, Siplus Et 200sp Cp 1543sp 1 Isec Firmware, Cp 1543 1 Firmware, Simatic Net Cp 1545 1 Firmware, Simatic Cp 1543sp 1 Firmware, Simatic Net Cp1243 7 Lte Eu Firmware, Simatic Cp 1243 7 Lte/us Firmware, Simatic Cp 1542sp 1 Firmware, Scalance Sc636 2c Firmware, Simatic Cp 1542sp 1 Irc Firmware, Scalance Sc642 2c Firmware, Scalance Sc646 2c Firmware, Scalance Sc622 2c Firmware, Siplus S7 1200 Cp 1243 1 Rail Firmware, Siplus S7 1200 Cp 1243 1 Firmware, Siplus Net Cp 1543 1 Firmware, Siplus Et 200sp Cp 1543sp 1 Isec Tx Rail Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 4.2.10 to 5.9.4 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.0 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 33 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Siplus Et 200sp Cp 1542sp 1 Irc Tx Rail | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Cp 1243 1 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Cp 1242 7 Gprs V2 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Net Cp 1243 8 Irc | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Scalance Sc632 2c | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Siplus Et 200sp Cp 1543sp 1 Isec | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Cp 1543 1 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Net Cp 1545 1 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Cp 1543sp 1 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Net Cp1243 7 Lte Eu | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Cp 1243 7 Lte/us | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Cp 1542sp 1 | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Scalance Sc636 2c | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Cp 1542sp 1 Irc | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Scalance Sc642 2c | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.3 |
| Running on/with | Platform Versions |
|---|---|
Siemens Scalance Sc646 2c | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Scalance Sc622 2c | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Siplus S7 1200 Cp 1243 1 Rail | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Siplus S7 1200 Cp 1243 1 | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Siplus Net Cp 1543 1 | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Siplus Et 200sp Cp 1543sp 1 Isec Tx Rail | All versions |
References (16)
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.