Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2010-3901

Опубликовано: 14 окт. 2010
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 6.4

Описание

OpenConnect before 2.25 does not properly validate X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary AnyConnect SSL VPN servers via a crafted server certificate that (1) does not correspond to the server hostname or (2) is presented in circumstances involving a missing --cafile configuration option.

РелизСтатусПримечание
dapper

DNE

devel

not-affected

2.25-0.1
hardy

DNE

jaunty

DNE

karmic

ignored

end of life
lucid

ignored

end of life
maverick

ignored

end of life
natty

not-affected

2.25-0.1
oneiric

not-affected

2.25-0.1
precise

not-affected

2.25-0.1

Показывать по

Ссылки на источники

EPSS

Процентиль: 46%
0.00598
Низкий

6.4 Medium

CVSS2

Связанные уязвимости

nvd
почти 16 лет назад

OpenConnect before 2.25 does not properly validate X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary AnyConnect SSL VPN servers via a crafted server certificate that (1) does not correspond to the server hostname or (2) is presented in circumstances involving a missing --cafile configuration option.

debian
почти 16 лет назад

OpenConnect before 2.25 does not properly validate X.509 certificates, ...

github
около 4 лет назад

OpenConnect before 2.25 does not properly validate X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary AnyConnect SSL VPN servers via a crafted server certificate that (1) does not correspond to the server hostname or (2) is presented in circumstances involving a missing --cafile configuration option.

EPSS

Процентиль: 46%
0.00598
Низкий

6.4 Medium

CVSS2