CVE-2021-41991
The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to fill the cache and later trigger the replacement of cache entries.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.20%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to fill the cache and later trigger the replacement of cache entries. The code attempts to select a less-often-used cache entry by means of a random number generator, but this is not done correctly. Remote code execution might be a slight possibility.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 5.20% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-190
- Affected
- strongswan/strongswan · debian/debian linux · fedoraproject/fedora · siemens/sinema remote connect server · siemens/siplus et 200sp cp 1542sp-1 irc tx rail firmware · siemens/simatic cp 1243-1 firmware · siemens/simatic cp 1242-7 gprs v2 firmware · siemens/simatic net cp 1243-8 irc firmware · siemens/scalance sc632-2c firmware · siemens/siplus et 200sp cp 1543sp-1 isec firmware · siemens/cp 1543-1 firmware · siemens/simatic net cp 1545-1 firmware · siemens/simatic cp 1543sp-1 firmware · siemens/simatic net cp1243-7 lte eu firmware · siemens/simatic cp 1243-7 lte\/us firmware · siemens/simatic cp 1542sp-1 firmware · siemens/scalance sc636-2c firmware · siemens/simatic cp 1542sp-1 irc firmware · siemens/scalance sc642-2c firmware · siemens/scalance sc646-2c firmware · +5 more
- Source
- cve@mitre.org
References
- https://cert-portal.siemens.com/productcert/pdf/ssa-539476.pdfPatch, Third Party Advisory
- https://github.com/strongswan/strongswan/releases/tag/5.9.4Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/10/msg00014.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5FJSATD2R2XHTG4P63GCMQ2N7EWKMME5/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WQSQ3BEC22NF4NCDZVCT4P3Q2ZIAJXGJ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y3TQ32JLJOBJDB2EJKSX2PBPB5NFG2D4/
- https://www.debian.org/security/2021/dsa-4989Third Party Advisory
- https://www.strongswan.org/blog/2021/10/18/strongswan-vulnerability-%28cve-2021-41991%29.html
- https://cert-portal.siemens.com/productcert/pdf/ssa-539476.pdfPatch, Third Party Advisory
- https://github.com/strongswan/strongswan/releases/tag/5.9.4Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/10/msg00014.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5FJSATD2R2XHTG4P63GCMQ2N7EWKMME5/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WQSQ3BEC22NF4NCDZVCT4P3Q2ZIAJXGJ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y3TQ32JLJOBJDB2EJKSX2PBPB5NFG2D4/
- https://www.debian.org/security/2021/dsa-4989Third Party Advisory
- https://www.strongswan.org/blog/2021/10/18/strongswan-vulnerability-%28cve-2021-41991%29.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.