Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-92px-2chv-hqhf

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

OpenConnect before 2.25 does not properly validate X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary AnyConnect SSL VPN servers via a crafted server certificate that (1) does not correspond to the server hostname or (2) is presented in circumstances involving a missing --cafile configuration option.

OpenConnect before 2.25 does not properly validate X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary AnyConnect SSL VPN servers via a crafted server certificate that (1) does not correspond to the server hostname or (2) is presented in circumstances involving a missing --cafile configuration option.

EPSS

Процентиль: 36%
0.00152
Низкий

Дефекты

CWE-20

Связанные уязвимости

ubuntu
больше 15 лет назад

OpenConnect before 2.25 does not properly validate X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary AnyConnect SSL VPN servers via a crafted server certificate that (1) does not correspond to the server hostname or (2) is presented in circumstances involving a missing --cafile configuration option.

nvd
больше 15 лет назад

OpenConnect before 2.25 does not properly validate X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary AnyConnect SSL VPN servers via a crafted server certificate that (1) does not correspond to the server hostname or (2) is presented in circumstances involving a missing --cafile configuration option.

debian
больше 15 лет назад

OpenConnect before 2.25 does not properly validate X.509 certificates, ...

EPSS

Процентиль: 36%
0.00152
Низкий

Дефекты

CWE-20