9.1
CVSSv3

CVE-2020-7043

Published: 27/02/2020 Updated: 07/11/2023
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.1 | Impact Score: 5.2 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

An issue exists in openfortivpn 1.11.0 when used with OpenSSL prior to 1.0.2. tunnel.c mishandles certificate validation because hostname comparisons do not consider '\0' characters, as demonstrated by a good.example.com\x00evil.example.com attack.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openfortivpn project openfortivpn

fedoraproject fedora 30

fedoraproject fedora 31

fedoraproject fedora 32

opensuse leap 15.1

opensuse backports sle 15.0

Github Repositories

Snyk C/C++ Test using Snyk Test API This is a proof of concept using experimental Snyk Test API for C and C++ packages The purpose of this project is to validate our assumptions about package identifications and gather feedback before commiting to a stable API WARNING: The API is experimental and will change! Getting started Set SNYK_TOKEN environment variable to contain your