SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-41990

The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature.

HIGH 7.5EPSS 6.65%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (6.65%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example, this can be triggered by an unrelated self-signed CA certificate sent by an initiator. Remote code execution cannot occur.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS
6.65% probability · 93th percentile
CISA KEV
Not listed
Weakness
CWE-190
Affected
strongswan/strongswan · debian/debian linux · fedoraproject/fedora · siemens/6gk6108-4am00-2ba2 firmware · siemens/6gk6108-4am00-2da2 firmware · siemens/6gk5804-0ap00-2aa2 firmware · siemens/6gk5812-1aa00-2aa2 firmware · siemens/6gk5812-1ba00-2aa2 firmware · siemens/6gk5816-1aa00-2aa2 firmware · siemens/6gk5816-1ba00-2aa2 firmware · siemens/6gk5826-2ab00-2ab2 firmware · siemens/6gk5874-2aa00-2aa2 firmware · siemens/6gk5874-3aa00-2aa2 firmware · siemens/6gk5876-3aa02-2ba2 firmware · siemens/6gk5876-3aa02-2ea2 firmware · siemens/6gk5876-4aa00-2ba2 firmware · siemens/6gk5876-4aa00-2da2 firmware · siemens/6gk5856-2ea00-3da1 firmware · siemens/6gk5856-2ea00-3aa1 firmware · siemens/6gk5615-0aa00-2aa2 firmware
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.