Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2cgw-c87g-ww8q

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.4

Описание

OpenVPN 3 Core Library version 3.6 and 3.6.1 allows a man-in-the-middle attacker to bypass the certificate authentication by issuing an unrelated server certificate using the same hostname found in the verify-x509-name option in a client configuration.

OpenVPN 3 Core Library version 3.6 and 3.6.1 allows a man-in-the-middle attacker to bypass the certificate authentication by issuing an unrelated server certificate using the same hostname found in the verify-x509-name option in a client configuration.

EPSS

Процентиль: 16%
0.00052
Низкий

7.4 High

CVSS3

Дефекты

CWE-287
CWE-295

Связанные уязвимости

CVSS3: 7.4
nvd
почти 4 года назад

OpenVPN 3 Core Library version 3.6 and 3.6.1 allows a man-in-the-middle attacker to bypass the certificate authentication by issuing an unrelated server certificate using the same hostname found in the verify-x509-name option in a client configuration.

CVSS3: 7.4
debian
почти 4 года назад

OpenVPN 3 Core Library version 3.6 and 3.6.1 allows a man-in-the-middl ...

EPSS

Процентиль: 16%
0.00052
Низкий

7.4 High

CVSS3

Дефекты

CWE-287
CWE-295