CVE-2015-3644

Severity CVSS v4.0:
Pending analysis
Type:
CWE-284 Improper Access Control
Publication date:
14/05/2015
Last modified:
12/04/2025

Description

Stunnel 5.00 through 5.13, when using the redirect option, does not redirect client connections to the expected server after the initial connection, which allows remote attackers to bypass authentication.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:stunnel:stunnel:5.00:*:*:*:*:*:*:*
cpe:2.3:a:stunnel:stunnel:5.01:*:*:*:*:*:*:*
cpe:2.3:a:stunnel:stunnel:5.02:*:*:*:*:*:*:*
cpe:2.3:a:stunnel:stunnel:5.03:*:*:*:*:*:*:*
cpe:2.3:a:stunnel:stunnel:5.04:*:*:*:*:*:*:*
cpe:2.3:a:stunnel:stunnel:5.05:*:*:*:*:*:*:*
cpe:2.3:a:stunnel:stunnel:5.06:*:*:*:*:*:*:*
cpe:2.3:a:stunnel:stunnel:5.07:*:*:*:*:*:*:*
cpe:2.3:a:stunnel:stunnel:5.08:*:*:*:*:*:*:*
cpe:2.3:a:stunnel:stunnel:5.09:*:*:*:*:*:*:*
cpe:2.3:a:stunnel:stunnel:5.10:*:*:*:*:*:*:*
cpe:2.3:a:stunnel:stunnel:5.11:*:*:*:*:*:*:*
cpe:2.3:a:stunnel:stunnel:5.12:*:*:*:*:*:*:*
cpe:2.3:a:stunnel:stunnel:5.13:*:*:*:*:*:*:*