5
CVSSv2

CVE-2020-7042

Published: 27/02/2020 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

An issue exists in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because the hostname check operates on uninitialized memory. The outcome is that a valid certificate is never accepted (only a malformed certificate may be accepted).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openfortivpn_project openfortivpn

fedoraproject fedora 30

fedoraproject fedora 31

fedoraproject fedora 32

opensuse leap 15.1

opensuse backports sle 15.0

Github Repositories

Snyk C/C++ Test using Snyk Test API This is a proof of concept using experimental Snyk Test API for C and C++ packages The purpose of this project is to validate our assumptions about package identifications and gather feedback before commiting to a stable API WARNING: The API is experimental and will change! Getting started Set SNYK_TOKEN environment variable to contain your