CVE-2021-41991
published 2021-10-18CVE-2021-41991: The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to fill the…
PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
4.84%
91.0th percentile
The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to fill the cache and later trigger the replacement of cache entries. The code attempts to select a less-often-used cache entry by means of a random number generator, but this is not done correctly. Remote code execution might be a slight possibility.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | strongswan | < strongswan 5.9.4-1 (bookworm) | strongswan 5.9.4-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | cbl2_strongswan_5.9.5-1_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_strongswan_5.7.2-4_on_cbl_mariner_1.0 | — | — |
| siemens | scalance_sc646-2c_firmware | < 2.3 | 2.3 |
| strongswan | strongswan | >= 0 < 5.9.1-1+deb11u1 | 5.9.1-1+deb11u1 |
| strongswan | strongswan | >= 0 < 5.9.4-1 | 5.9.4-1 |
| strongswan | strongswan | >= 0 < 5.9.4-1 | 5.9.4-1 |
| strongswan | strongswan | >= 0 < 5.9.4-1 | 5.9.4-1 |
| strongswan | strongswan | >= 0 < 5.6.2-1ubuntu2.7 | 5.6.2-1ubuntu2.7 |
| strongswan | strongswan | >= 0 < 5.8.2-1ubuntu3.3 | 5.8.2-1ubuntu3.3 |
| strongswan | strongswan | >= 0 < 5.1.2-0ubuntu2.11+esm1 | 5.1.2-0ubuntu2.11+esm1 |
| strongswan | strongswan | >= 0 < 5.3.5-1ubuntu3.8+esm1 | 5.3.5-1ubuntu3.8+esm1 |
| strongswan | strongswan | >= 4.2.10 < 5.9.4 | 5.9.4 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC NET CP, SINEMA, and SCALANCE
cisa_ics·2025-09-16·CVSS 7.5
[HIGH] Siemens SIMATIC NET CP, SINEMA, and SCALANCE
ICS Advisory
##
Siemens SIMATIC NET CP, SINEMA, and SCALANCE
Release DateSeptember 16, 2025
Alert CodeICSA-25-259-03
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.5
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC NET CP, SINEMA and SCALANCE
- Vulnerabilities: Integer Overflow or Wraparound
## 2. RISK EVALUATION
S
Ubuntu
strongSwan vulnerabilities
vendor_ubuntu·2021-10-19·CVSS 7.5
CVE-2021-41991 [HIGH] strongSwan vulnerabilities
Title: strongSwan vulnerabilities
Summary: Several security issues were fixed in strongSwan.
It was discovered that strongSwan incorrectly handled certain RSASSA-PSS
signatures. A remote attacker could use this issue to cause strongSwan to
crash, resulting in a denial of service. (CVE-2021-41990)
It was discovered that strongSwan incorrectly handled replacing
certificates in the cache. A remote attacker could use this issue to cause
strongSwan to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2021-41991)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
strongSwan vulnerability
vendor_ubuntu·2021-10-19·CVSS 7.5
CVE-2021-41991 [HIGH] strongSwan vulnerability
Title: strongSwan vulnerability
Summary: Several security issues were fixed in strongSwan.
USN-5111-1 fixed a vulnerability in strongSwan. This update provides
the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.
Original advisory details:
It was discovered that strongSwan incorrectly handled replacing
certificates in the cache. A remote attacker could use this issue to cause
strongSwan to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2021-41991)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
strongswan: integer overflow when replacing certificates in cache
vendor_redhat·2021-10-18·CVSS 7.5
CVE-2021-41991 [HIGH] CWE-190 strongswan: integer overflow when replacing certificates in cache
strongswan: integer overflow when replacing certificates in cache
The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to fill the cache and later trigger the replacement of cache entries. The code attempts to select a less-often-used cache entry by means of a random number generator, but this is not done correctly. Remote code execution might be a slight possibility.
Package: strongimcv (Red Hat Enterprise Linux 7) - Out of support scope
Microsoft
The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to fill the cache and later trigger the replacement of
vendor_msrc·2021-10-12·CVSS 7.5
CVE-2021-41991 [HIGH] CWE-190 The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to fill the cache and later trigger the replacement of
The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to fill the cache and later trigger the replacement of cache entries. The code attempts to select a less-often-used cache entry by means of a random number generator but this is not done correctly. Remote code execution might be a slight possibility.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed
Debian
CVE-2021-41991: strongswan - The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer ...
vendor_debian·2021·CVSS 7.5
CVE-2021-41991 [HIGH] CVE-2021-41991: strongswan - The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer ...
The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to fill the cache and later trigger the replacement of cache entries. The code attempts to select a less-often-used cache entry by means of a random number generator, but this is not done correctly. Remote code execution might be a slight possibility.
Scope: local
bookworm: resolved (fixed in 5.9.4-1)
bullseye: resolved (fixed in 5.9.1-1+deb11u1)
forky: resolved (fixed in 5.9.4-1)
sid: resolved (fixed in 5.9.4-1)
trixie: resolved (fixed in 5.9.4-1)
GHSA
GHSA-jpr7-w98h-cvgm: The in-memory certificate cache in strongSwan before 5
ghsa_unreviewed·2022-05-24
CVE-2021-41991 [HIGH] CWE-190 GHSA-jpr7-w98h-cvgm: The in-memory certificate cache in strongSwan before 5
The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to fill the cache and later trigger the replacement of cache entries. The code attempts to select a less-often-used cache entry by means of a random number generator, but this is not done correctly. Remote code execution might be a slight possibility.
OSV
strongswan vulnerability
osv·2021-10-19·CVSS 7.5
CVE-2021-41991 [HIGH] strongswan vulnerability
strongswan vulnerability
USN-5111-1 fixed a vulnerability in strongSwan. This update provides
the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.
Original advisory details:
It was discovered that strongSwan incorrectly handled replacing
certificates in the cache. A remote attacker could use this issue to cause
strongSwan to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2021-41991)
OSV
strongswan vulnerabilities
osv·2021-10-19·CVSS 7.5
CVE-2021-41990 [HIGH] strongswan vulnerabilities
strongswan vulnerabilities
It was discovered that strongSwan incorrectly handled certain RSASSA-PSS
signatures. A remote attacker could use this issue to cause strongSwan to
crash, resulting in a denial of service. (CVE-2021-41990)
It was discovered that strongSwan incorrectly handled replacing
certificates in the cache. A remote attacker could use this issue to cause
strongSwan to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2021-41991)
OSV
CVE-2021-41991: The in-memory certificate cache in strongSwan before 5
osv·2021-10-18·CVSS 7.5
CVE-2021-41991 [HIGH] CVE-2021-41991: The in-memory certificate cache in strongSwan before 5
The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to fill the cache and later trigger the replacement of cache entries. The code attempts to select a less-often-used cache entry by means of a random number generator, but this is not done correctly. Remote code execution might be a slight possibility.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://cert-portal.siemens.com/productcert/pdf/ssa-539476.pdfhttps://github.com/strongswan/strongswan/releases/tag/5.9.4https://lists.debian.org/debian-lts-announce/2021/10/msg00014.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5FJSATD2R2XHTG4P63GCMQ2N7EWKMME5/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WQSQ3BEC22NF4NCDZVCT4P3Q2ZIAJXGJ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y3TQ32JLJOBJDB2EJKSX2PBPB5NFG2D4/https://www.debian.org/security/2021/dsa-4989https://www.strongswan.org/blog/2021/10/18/strongswan-vulnerability-%28cve-2021-41991%29.htmlhttps://cert-portal.siemens.com/productcert/pdf/ssa-539476.pdfhttps://github.com/strongswan/strongswan/releases/tag/5.9.4https://lists.debian.org/debian-lts-announce/2021/10/msg00014.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5FJSATD2R2XHTG4P63GCMQ2N7EWKMME5/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WQSQ3BEC22NF4NCDZVCT4P3Q2ZIAJXGJ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y3TQ32JLJOBJDB2EJKSX2PBPB5NFG2D4/https://www.debian.org/security/2021/dsa-4989https://www.strongswan.org/blog/2021/10/18/strongswan-vulnerability-%28cve-2021-41991%29.html
2021-10-18
Published