← Back

CVE-2021-41991

nvd nist
Published: Oct 18, 2021Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to fill the cache and later trigger the replacement of cache entries. The code attempts to select a less-often-used cache entry by means of a random number generator, but this is not done correctly. Remote code execution might be a slight possibility.

Affected (29)

Show all products
1 product
Strongswan
1 product
Debian Linux
1 product
Fedora
22 products
Sinema Remote Connect Server
Simatic Cp 1243 1 Firmware
Scalance Sc632 2c Firmware
Cp 1543 1 Firmware
Simatic Net Cp 1545 1 Firmware
Simatic Cp 1543sp 1 Firmware
Simatic Cp 1243 7 Lte/us Firmware
Simatic Cp 1542sp 1 Firmware
Scalance Sc636 2c Firmware
Simatic Cp 1542sp 1 Irc Firmware
Scalance Sc642 2c Firmware
Scalance Sc646 2c Firmware
Scalance Sc622 2c Firmware
Siplus S7 1200 Cp 1243 1 Firmware
Siplus Net Cp 1543 1 Firmware
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 4.2.10 to 5.9.4
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 10.0
Version 11.0
Version 9.0
Configuration C
3 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 33
Version 34
Version 35
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Siemens
Siplus Et 200sp Cp 1542sp 1 Irc Tx Rail
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Siemens
Simatic Cp 1243 1
All versions
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Siemens
Simatic Cp 1242 7 Gprs V2
All versions
Configuration H
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Siemens
Simatic Net Cp 1243 8 Irc
All versions
Configuration I
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Siemens
Scalance Sc632 2c
All versions
Configuration J
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Siemens
Siplus Et 200sp Cp 1543sp 1 Isec
All versions
Configuration K
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Siemens
Cp 1543 1
All versions
Configuration L
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Siemens
Simatic Net Cp 1545 1
All versions
Configuration M
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Siemens
Simatic Cp 1543sp 1
All versions
Configuration N
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Siemens
Simatic Net Cp1243 7 Lte Eu
All versions
Configuration O
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Siemens
Simatic Cp 1243 7 Lte/us
All versions
Configuration P
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Siemens
Simatic Cp 1542sp 1
All versions
Configuration Q
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Siemens
Scalance Sc636 2c
All versions
Configuration R
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Siemens
Simatic Cp 1542sp 1 Irc
All versions
Configuration S
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Siemens
Scalance Sc642 2c
All versions
Configuration T
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.3
Running on/withPlatform Versions
Siemens
Scalance Sc646 2c
All versions
Configuration U
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Siemens
Scalance Sc622 2c
All versions
Configuration V
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Siemens
Siplus S7 1200 Cp 1243 1 Rail
All versions
Configuration W
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Siemens
Siplus S7 1200 Cp 1243 1
All versions
Configuration X
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Siemens
Siplus Net Cp 1543 1
All versions
Configuration Y
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Siemens
Siplus Et 200sp Cp 1543sp 1 Isec Tx Rail
All versions

References (16)

Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.