CVE-2010-3901
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
14/10/2010
Last modified:
11/04/2025
Description
OpenConnect before 2.25 does not properly validate X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary AnyConnect SSL VPN servers via a crafted server certificate that (1) does not correspond to the server hostname or (2) is presented in circumstances involving a missing --cafile configuration option.
Impact
Base Score 2.0
6.40
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:infradead:openconnect:*:*:*:*:*:*:*:* | 2.22 (including) | |
cpe:2.3:a:infradead:openconnect:1.00:*:*:*:*:*:*:* | ||
cpe:2.3:a:infradead:openconnect:1.10:*:*:*:*:*:*:* | ||
cpe:2.3:a:infradead:openconnect:1.20:*:*:*:*:*:*:* | ||
cpe:2.3:a:infradead:openconnect:1.30:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://www.infradead.org/openconnect.html
- http://www.openwall.com/lists/oss-security/2010/08/01/1
- http://www.openwall.com/lists/oss-security/2010/08/02/7
- http://www.infradead.org/openconnect.html
- http://www.openwall.com/lists/oss-security/2010/08/01/1
- http://www.openwall.com/lists/oss-security/2010/08/02/7