<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 04:57:08 +0000</lastBuildDate>
    <item>
      <title>certfr-2022-avi-124 — De multiples vulnérabilités ont été découvertes dans les produits
Siemens. Certaines d'entre elles permettent à un atta…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-124</link>
      <description>certfr-2022-avi-124</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-124</guid>
    </item>
    <item>
      <title>EUVD-2026-31961</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-31961</link>
      <description>EUVD-2026-31961</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-31961</guid>
    </item>
    <item>
      <title>fkie_cve-2021-41990</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-41990</link>
      <description>&lt;p&gt;The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example, this can be triggered by an unrelated self-signed CA certificate sent by an initiator. Remote code execution cannot occur.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example, this can be triggered by an unrelated self-signed CA certificate sent by an initiator. Remote code execution cannot occur.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-41990</guid>
    </item>
    <item>
      <title>GHSA-3wp5-cvp4-5h42</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3wp5-cvp4-5h42</link>
      <description>&lt;p&gt;The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example, this can be triggered by an unrelated self-signed CA certificate sent by an initiator. Remote code execution cannot occur.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example, this can be triggered by an unrelated self-signed CA certificate sent by an initiator. Remote code execution cannot occur.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3wp5-cvp4-5h42</guid>
    </item>
    <item>
      <title>gsd-2021-41990</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-41990</link>
      <description>gsd-2021-41990</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-41990</guid>
    </item>
    <item>
      <title>ICSA-25-259-03 — Siemens SIMATIC NET CP, SINEMA and SCALANCE</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-25-259-03</link>
      <description>&lt;p&gt;The gmp plugin in strongSwan before version 5.9.4 has a remote integer overflow vulnerability via a crafted certificate with an RSASSA-PSS signature. For example, this can be triggered by an unrelated self-signed CA certificate sent by an initiator. Remote code execution cannot occur. The in-memory certificate cache in strongSwan before version 5.9.4 has a remote integer overflow vulnerability upon receiving many requests with different certificates to fill the cache and later trigger the replacement of cache entries. The code attempts to select a less-often-used cache entry by means of a random number generator, but this is not done correctly. This could lead to a denial of service (DoS) condition. Remote code execution can&amp;#39;t be excluded completely, but it would require attackers to have control over the dereferenced memory, so it is very unlikely.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The gmp plugin in strongSwan before version 5.9.4 has a remote integer overflow vulnerability via a crafted certificate with an RSASSA-PSS signature. For example, this can be triggered by an unrelated self-signed CA certificate sent by an initiator. Remote code execution cannot occur. The in-memory certificate cache in strongSwan before version 5.9.4 has a remote integer overflow vulnerability upon receiving many requests with different certificates to fill the cache and later trigger the replacement of cache entries. The code attempts to select a less-often-used cache entry by means of a random number generator, but this is not done correctly. This could lead to a denial of service (DoS) condition. Remote code execution can&amp;#39;t be excluded completely, but it would require attackers to have control over the dereferenced memory, so it is very unlikely.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-25-259-03</guid>
    </item>
    <item>
      <title>msrc_CVE-2021-41990 — The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS si…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2021-41990</link>
      <description>msrc_CVE-2021-41990</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2021-41990</guid>
    </item>
    <item>
      <title>OESA-2021-1408 — strongswan security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2021-1408</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: strongswan, openEuler:20.03-LTS-SP2: strongswan&lt;/p&gt;
&lt;p&gt;The strongSwan IPsec implementation supports both the IKEv1 and IKEv2 key exchange protocols in conjunction with the native NETKEY IPsec stack of the Linux kernel.&#13;
&#13;
Security Fix(es):&#13;
&#13;
The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example, this can be triggered by an unrelated self-signed CA certificate sent by an initiator. Remote code execution cannot occur.(CVE-2021-41990)&#13;
&#13;
The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to fill the cache and later trigger the replacement of cache entries. The code attempts to select a less-often-used cache entry by means of a random number generator, but this is not done correctly. Remote code execution might be a slight possibility.(CVE-2021-41991)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: strongswan, openEuler:20.03-LTS-SP2: strongswan&lt;/p&gt;
&lt;p&gt;The strongSwan IPsec implementation supports both the IKEv1 and IKEv2 key exchange protocols in conjunction with the native NETKEY IPsec stack of the Linux kernel.&#13;
&#13;
Security Fix(es):&#13;
&#13;
The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example, this can be triggered by an unrelated self-signed CA certificate sent by an initiator. Remote code execution cannot occur.(CVE-2021-41990)&#13;
&#13;
The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to fill the cache and later trigger the replacement of cache entries. The code attempts to select a less-often-used cache entry by means of a random number generator, but this is not done correctly. Remote code execution might be a slight possibility.(CVE-2021-41991)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2021-1408</guid>
    </item>
    <item>
      <title>openSUSE-SU-2021:1399-1 — Security update for strongswan</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2021:1399-1</link>
      <description>&lt;p&gt;Security update for strongswan&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for strongswan&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2021:1399-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2021:3467-1 — Security update for strongswan</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2021:3467-1</link>
      <description>&lt;p&gt;Security update for strongswan&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for strongswan&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2021:3467-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-41990</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-41990</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: strongswan, Ubuntu:Pro:FIPS-updates:18.04:LTS: strongswan, Ubuntu:Pro:FIPS:18.04:LTS: strongswan, Ubuntu:20.04:LTS: strongswan, Ubuntu:Pro:FIPS-updates:20.04:LTS: strongswan, Ubuntu:Pro:FIPS:20.04:LTS: strongswan, Ubuntu:22.04:LTS: strongswan&lt;/p&gt;
&lt;p&gt;The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example, this can be triggered by an unrelated self-signed CA certificate sent by an initiator. Remote code execution cannot occur.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: strongswan, Ubuntu:Pro:FIPS-updates:18.04:LTS: strongswan, Ubuntu:Pro:FIPS:18.04:LTS: strongswan, Ubuntu:20.04:LTS: strongswan, Ubuntu:Pro:FIPS-updates:20.04:LTS: strongswan, Ubuntu:Pro:FIPS:20.04:LTS: strongswan, Ubuntu:22.04:LTS: strongswan&lt;/p&gt;
&lt;p&gt;The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example, this can be triggered by an unrelated self-signed CA certificate sent by an initiator. Remote code execution cannot occur.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-41990</guid>
    </item>
    <item>
      <title>VDE-2022-010 — PHOENIX CONTACT: Multiple Linux component vulnerabilities fixed in latest AXC F x152 LTS release</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2022-010</link>
      <description>&lt;p&gt;PLCnext Control AXC F x152 is certified according to IEC 62443-4-1 and IEC 62443-4-2.
This certification requires that all third-party components used in the firmware are regularly checked for known vulnerabilities.&lt;/p&gt;
&lt;p&gt;Firmware components in version 2021.06 had already been updated. For the 2022.0 LTS version more firmware components have been updated implicitly fixing the vulnerabilities listed. The vulnerabilities listed above have not been individually verified in terms of actual impact and/or limitations in combination with the affected products listed. The current LTS release 2022.0 LTS contains updates of integrated third-party libraries, SDKs and other third-party software to address these issues nevertheless.&lt;/p&gt;
&lt;p&gt;UPDATE A (April 4th, 2022): Added RFC 4072 (Art. No. 1051328) and fixed affected version of AXC F 3152&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;PLCnext Control AXC F x152 is certified according to IEC 62443-4-1 and IEC 62443-4-2.
This certification requires that all third-party components used in the firmware are regularly checked for known vulnerabilities.&lt;/p&gt;
&lt;p&gt;Firmware components in version 2021.06 had already been updated. For the 2022.0 LTS version more firmware components have been updated implicitly fixing the vulnerabilities listed. The vulnerabilities listed above have not been individually verified in terms of actual impact and/or limitations in combination with the affected products listed. The current LTS release 2022.0 LTS contains updates of integrated third-party libraries, SDKs and other third-party software to address these issues nevertheless.&lt;/p&gt;
&lt;p&gt;UPDATE A (April 4th, 2022): Added RFC 4072 (Art. No. 1051328) and fixed affected version of AXC F 3152&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2022-010</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-1024 — strongSwan: Mehrere Schwachstellen ermöglichen Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1024</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in strongSwan ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in strongSwan ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1024</guid>
    </item>
  </channel>
</rss>
