Msrc Cbl2 Strongswan 5.9.5-1 On Cbl Mariner 2.0 vulnerabilities
3 known vulnerabilities affecting msrc/cbl2_strongswan_5.9.5-1_on_cbl_mariner_2.0.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2
Vulnerabilities
Page 1 of 1
CVE-2021-45079CRITICALCVSS 9.12022-01-11
CVE-2021-45079 [CRITICAL] CWE-476 In strongSwan before 5.9.5 a malicious responder can send an EAP-Success message too early without actually authenticating the client and (in the case of EAP methods with mutual authentication and EAP
In strongSwan before 5.9.5 a malicious responder can send an EAP-Success message too early without actually authenticating the client and (in the case of EAP methods with mutual authentication and EAP-only authentication for IKEv2) even without server authenticatio
msrc
CVE-2021-41990HIGHCVSS 7.52021-10-12
CVE-2021-41990 [HIGH] CWE-190 The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example this can be triggered by an unrelated self-signed CA certifi
The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example this can be triggered by an unrelated self-signed CA certificate sent by an initiator. Remote code execution cannot occur.
FAQ:
msrc
CVE-2021-41991HIGHCVSS 7.52021-10-12
CVE-2021-41991 [HIGH] CWE-190 The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to fill the cache and later trigger the replacement of
The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to fill the cache and later trigger the replacement of cache entries. The code attempts to select a less-often-used cache e
msrc