CVE-2021-41990
published 2021-10-18CVE-2021-41990: The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example, this can be…
PriorityP345high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
6.49%
93.0th percentile
The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example, this can be triggered by an unrelated self-signed CA certificate sent by an initiator. Remote code execution cannot occur.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | strongswan | < strongswan 5.9.4-1 (bookworm) | strongswan 5.9.4-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | cbl2_strongswan_5.9.5-1_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_strongswan_5.7.2-4_on_cbl_mariner_1.0 | — | — |
| strongswan | strongswan | >= 0 < 5.9.1-1+deb11u1 | 5.9.1-1+deb11u1 |
| strongswan | strongswan | >= 0 < 5.9.4-1 | 5.9.4-1 |
| strongswan | strongswan | >= 0 < 5.9.4-1 | 5.9.4-1 |
| strongswan | strongswan | >= 0 < 5.9.4-1 | 5.9.4-1 |
| strongswan | strongswan | >= 0 < 5.6.2-1ubuntu2.7 | 5.6.2-1ubuntu2.7 |
| strongswan | strongswan | >= 0 < 5.8.2-1ubuntu3.3 | 5.8.2-1ubuntu3.3 |
| strongswan | strongswan | >= 5.6.1 < 5.9.4 | 5.9.4 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3wp5-cvp4-5h42: The gmp plugin in strongSwan before 5
ghsa_unreviewed·2022-05-24
CVE-2021-41990 [HIGH] CWE-190 GHSA-3wp5-cvp4-5h42: The gmp plugin in strongSwan before 5
The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example, this can be triggered by an unrelated self-signed CA certificate sent by an initiator. Remote code execution cannot occur.
OSV
strongswan vulnerabilities
osv·2021-10-19·CVSS 7.5
CVE-2021-41990 [HIGH] strongswan vulnerabilities
strongswan vulnerabilities
It was discovered that strongSwan incorrectly handled certain RSASSA-PSS
signatures. A remote attacker could use this issue to cause strongSwan to
crash, resulting in a denial of service. (CVE-2021-41990)
It was discovered that strongSwan incorrectly handled replacing
certificates in the cache. A remote attacker could use this issue to cause
strongSwan to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2021-41991)
OSV
CVE-2021-41990: The gmp plugin in strongSwan before 5
osv·2021-10-18·CVSS 7.5
CVE-2021-41990 [HIGH] CVE-2021-41990: The gmp plugin in strongSwan before 5
The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example, this can be triggered by an unrelated self-signed CA certificate sent by an initiator. Remote code execution cannot occur.
CISA ICS
Siemens SIMATIC NET CP, SINEMA, and SCALANCE
cisa_ics·2025-09-16·CVSS 7.5
[HIGH] Siemens SIMATIC NET CP, SINEMA, and SCALANCE
ICS Advisory
##
Siemens SIMATIC NET CP, SINEMA, and SCALANCE
Release DateSeptember 16, 2025
Alert CodeICSA-25-259-03
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.5
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC NET CP, SINEMA and SCALANCE
- Vulnerabilities: Integer Overflow or Wraparound
## 2. RISK EVALUATION
S
Ubuntu
strongSwan vulnerabilities
vendor_ubuntu·2021-10-19·CVSS 7.5
CVE-2021-41991 [HIGH] strongSwan vulnerabilities
Title: strongSwan vulnerabilities
Summary: Several security issues were fixed in strongSwan.
It was discovered that strongSwan incorrectly handled certain RSASSA-PSS
signatures. A remote attacker could use this issue to cause strongSwan to
crash, resulting in a denial of service. (CVE-2021-41990)
It was discovered that strongSwan incorrectly handled replacing
certificates in the cache. A remote attacker could use this issue to cause
strongSwan to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2021-41991)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
strongswan: gmp plugin: integer overflow via a crafted certificate with an RSASSA-PSS signature
vendor_redhat·2021-10-18·CVSS 7.5
CVE-2021-41990 [HIGH] CWE-190 strongswan: gmp plugin: integer overflow via a crafted certificate with an RSASSA-PSS signature
strongswan: gmp plugin: integer overflow via a crafted certificate with an RSASSA-PSS signature
The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example, this can be triggered by an unrelated self-signed CA certificate sent by an initiator. Remote code execution cannot occur.
Package: strongimcv (Red Hat Enterprise Linux 7) - Not affected
Microsoft
The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example this can be triggered by an unrelated self-signed CA certifi
vendor_msrc·2021-10-12·CVSS 7.5
CVE-2021-41990 [HIGH] CWE-190 The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example this can be triggered by an unrelated self-signed CA certifi
The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example this can be triggered by an unrelated self-signed CA certificate sent by an initiator. Remote code execution cannot occur.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If i
Debian
CVE-2021-41990: strongswan - The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a cr...
vendor_debian·2021·CVSS 7.5
CVE-2021-41990 [HIGH] CVE-2021-41990: strongswan - The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a cr...
The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example, this can be triggered by an unrelated self-signed CA certificate sent by an initiator. Remote code execution cannot occur.
Scope: local
bookworm: resolved (fixed in 5.9.4-1)
bullseye: resolved (fixed in 5.9.1-1+deb11u1)
forky: resolved (fixed in 5.9.4-1)
sid: resolved (fixed in 5.9.4-1)
trixie: resolved (fixed in 5.9.4-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://cert-portal.siemens.com/productcert/pdf/ssa-539476.pdfhttps://github.com/strongswan/strongswan/releases/tag/5.9.4https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5FJSATD2R2XHTG4P63GCMQ2N7EWKMME5/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WQSQ3BEC22NF4NCDZVCT4P3Q2ZIAJXGJ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y3TQ32JLJOBJDB2EJKSX2PBPB5NFG2D4/https://www.debian.org/security/2021/dsa-4989https://www.strongswan.org/blog/2021/10/18/strongswan-vulnerability-%28cve-2021-41990%29.htmlhttps://cert-portal.siemens.com/productcert/pdf/ssa-539476.pdfhttps://github.com/strongswan/strongswan/releases/tag/5.9.4https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5FJSATD2R2XHTG4P63GCMQ2N7EWKMME5/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WQSQ3BEC22NF4NCDZVCT4P3Q2ZIAJXGJ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y3TQ32JLJOBJDB2EJKSX2PBPB5NFG2D4/https://www.debian.org/security/2021/dsa-4989https://www.strongswan.org/blog/2021/10/18/strongswan-vulnerability-%28cve-2021-41990%29.html
2021-10-18
Published