6.4
CVSSv2

CVE-2020-7043

Published: 27/02/2020 Updated: 07/11/2023
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.1 | Impact Score: 5.2 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

An issue exists in openfortivpn 1.11.0 when used with OpenSSL prior to 1.0.2. tunnel.c mishandles certificate validation because hostname comparisons do not consider '\0' characters, as demonstrated by a good.example.com\x00evil.example.com attack.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openfortivpn_project openfortivpn

fedoraproject fedora 30

fedoraproject fedora 31

fedoraproject fedora 32

opensuse leap 15.1

opensuse backports sle 15.0

Github Repositories

Snyk C/C++ Test using Snyk Test API This is a proof of concept using experimental Snyk Test API for C and C++ packages The purpose of this project is to validate our assumptions about package identifications and gather feedback before commiting to a stable API WARNING: The API is experimental and will change! Getting started Set SNYK_TOKEN environment variable to contain your