CVE-2021-41990 - CVE House
Back to Database
Status published High CVE-2021-41990

The gmp plugin in strongSwan before 5.9.4 has a remote...

Vulnerability Description

The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example, this can be triggered by an unrelated self-signed CA certificate sent by an initiator. Remote code execution cannot occur.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-41990

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

strongswan, debian linux, fedora, 6gk6108-4am00-2ba2 firmware, 6gk6108-4am00-2da2 firmware, 6gk5804-0ap00-2aa2 firmware, 6gk5812-1aa00-2aa2 firmware, 6gk5812-1ba00-2aa2 firmware, 6gk5816-1aa00-2aa2 firmware, 6gk5816-1ba00-2aa2 firmware, 6gk5826-2ab00-2ab2 firmware, 6gk5874-2aa00-2aa2 firmware, 6gk5874-3aa00-2aa2 firmware, 6gk5876-3aa02-2ba2 firmware, 6gk5876-3aa02-2ea2 firmware, 6gk5876-4aa00-2ba2 firmware, 6gk5876-4aa00-2da2 firmware, 6gk5856-2ea00-3da1 firmware, 6gk5856-2ea00-3aa1 firmware, 6gk5615-0aa00-2aa2 firmware
Vulnerable Versions:
5.6.1, 10.0, 11.0, 33, 34, 35

Timeline

Official Publish: October 18th, 2021
Last Modified: August 4th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.