CVE-2021-41991 - CVE House
Back to Database
Status published High CVE-2021-41991

The in-memory certificate cache in strongSwan before 5.9.4 has a...

Vulnerability Description

The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to fill the cache and later trigger the replacement of cache entries. The code attempts to select a less-often-used cache entry by means of a random number generator, but this is not done correctly. Remote code execution might be a slight possibility.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-41991

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

strongswan, debian linux, fedora, sinema remote connect server, siplus et 200sp cp 1542sp-1 irc tx rail firmware, simatic cp 1243-1 firmware, simatic cp 1242-7 gprs v2 firmware, simatic net cp 1243-8 irc firmware, scalance sc632-2c firmware, siplus et 200sp cp 1543sp-1 isec firmware, cp 1543-1 firmware, simatic net cp 1545-1 firmware, simatic cp 1543sp-1 firmware, simatic net cp1243-7 lte eu firmware, simatic cp 1243-7 lte\/us firmware, simatic cp 1542sp-1 firmware, scalance sc636-2c firmware, simatic cp 1542sp-1 irc firmware, scalance sc642-2c firmware, scalance sc646-2c firmware, scalance sc622-2c firmware, siplus s7-1200 cp 1243-1 rail firmware, siplus s7-1200 cp 1243-1 firmware, siplus net cp 1543-1 firmware, siplus et 200sp cp 1543sp-1 isec tx rail firmware
Vulnerable Versions:
4.2.10, 9.0, 10.0, 11.0, 33, 34, 35, 0

Timeline

Official Publish: October 18th, 2021
Last Modified: August 4th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.