<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T04:57:54.996014+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-124</id>
    <title>certfr-2022-avi-124 — De multiples vulnérabilités ont été découvertes dans les produits
Siemens. Certaines d'entre elles permettent à un atta…</title>
    <updated>2026-10-03T04:57:55.027011+00:00</updated>
    <content>certfr-2022-avi-124</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-124"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-31961</id>
    <title>EUVD-2026-31961</title>
    <updated>2026-10-03T04:57:55.027061+00:00</updated>
    <content>EUVD-2026-31961</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-31961"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-41990</id>
    <title>fkie_cve-2021-41990</title>
    <updated>2026-10-03T04:57:55.027078+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example, this can be triggered by an unrelated self-signed CA certificate sent by an initiator. Remote code execution cannot occur.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-41990"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3wp5-cvp4-5h42</id>
    <title>GHSA-3wp5-cvp4-5h42</title>
    <updated>2026-10-03T04:57:55.027108+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example, this can be triggered by an unrelated self-signed CA certificate sent by an initiator. Remote code execution cannot occur.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3wp5-cvp4-5h42"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-41990</id>
    <title>gsd-2021-41990</title>
    <updated>2026-10-03T04:57:55.027124+00:00</updated>
    <content>gsd-2021-41990</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-41990"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-25-259-03</id>
    <title>ICSA-25-259-03 — Siemens SIMATIC NET CP, SINEMA and SCALANCE</title>
    <updated>2026-10-03T04:57:55.027135+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The gmp plugin in strongSwan before version 5.9.4 has a remote integer overflow vulnerability via a crafted certificate with an RSASSA-PSS signature. For example, this can be triggered by an unrelated self-signed CA certificate sent by an initiator. Remote code execution cannot occur. The in-memory certificate cache in strongSwan before version 5.9.4 has a remote integer overflow vulnerability upon receiving many requests with different certificates to fill the cache and later trigger the replacement of cache entries. The code attempts to select a less-often-used cache entry by means of a random number generator, but this is not done correctly. This could lead to a denial of service (DoS) condition. Remote code execution can't be excluded completely, but it would require attackers to have control over the dereferenced memory, so it is very unlikely.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-25-259-03"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2021-41990</id>
    <title>msrc_CVE-2021-41990 — The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS si…</title>
    <updated>2026-10-03T04:57:55.027161+00:00</updated>
    <content>msrc_CVE-2021-41990</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2021-41990"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2021-1408</id>
    <title>OESA-2021-1408 — strongswan security update</title>
    <updated>2026-10-03T04:57:55.027177+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: strongswan, openEuler:20.03-LTS-SP2: strongswan</p>
<p>The strongSwan IPsec implementation supports both the IKEv1 and IKEv2 key exchange protocols in conjunction with the native NETKEY IPsec stack of the Linux kernel.

Security Fix(es):

The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example, this can be triggered by an unrelated self-signed CA certificate sent by an initiator. Remote code execution cannot occur.(CVE-2021-41990)

The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to fill the cache and later trigger the replacement of cache entries. The code attempts to select a less-often-used cache entry by means of a random number generator, but this is not done correctly. Remote code execution might be a slight possibility.(CVE-2021-41991)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2021-1408"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2021:1399-1</id>
    <title>openSUSE-SU-2021:1399-1 — Security update for strongswan</title>
    <updated>2026-10-03T04:57:55.027206+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for strongswan</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2021:1399-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2021:3467-1</id>
    <title>SUSE-SU-2021:3467-1 — Security update for strongswan</title>
    <updated>2026-10-03T04:57:55.027237+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for strongswan</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2021:3467-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-41990</id>
    <title>UBUNTU-CVE-2021-41990</title>
    <updated>2026-10-03T04:57:55.027269+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:18.04:LTS: strongswan, Ubuntu:Pro:FIPS-updates:18.04:LTS: strongswan, Ubuntu:Pro:FIPS:18.04:LTS: strongswan, Ubuntu:20.04:LTS: strongswan, Ubuntu:Pro:FIPS-updates:20.04:LTS: strongswan, Ubuntu:Pro:FIPS:20.04:LTS: strongswan, Ubuntu:22.04:LTS: strongswan</p>
<p>The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example, this can be triggered by an unrelated self-signed CA certificate sent by an initiator. Remote code execution cannot occur.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-41990"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2022-010</id>
    <title>VDE-2022-010 — PHOENIX CONTACT: Multiple Linux component vulnerabilities fixed in latest AXC F x152 LTS release</title>
    <updated>2026-10-03T04:57:55.027299+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>PLCnext Control AXC F x152 is certified according to IEC 62443-4-1 and IEC 62443-4-2.
This certification requires that all third-party components used in the firmware are regularly checked for known vulnerabilities.</p>
<p>Firmware components in version 2021.06 had already been updated. For the 2022.0 LTS version more firmware components have been updated implicitly fixing the vulnerabilities listed. The vulnerabilities listed above have not been individually verified in terms of actual impact and/or limitations in combination with the affected products listed. The current LTS release 2022.0 LTS contains updates of integrated third-party libraries, SDKs and other third-party software to address these issues nevertheless.</p>
<p>UPDATE A (April 4th, 2022): Added RFC 4072 (Art. No. 1051328) and fixed affected version of AXC F 3152</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2022-010"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1024</id>
    <title>WID-SEC-W-2024-1024 — strongSwan: Mehrere Schwachstellen ermöglichen Denial of Service</title>
    <updated>2026-10-03T04:57:55.027368+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in strongSwan ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1024"/>
  </entry>
</feed>
